---
id: CVE-2026-73057
title: >-
  stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy
  endpoint, allowing attackers to cause denial of service by memory exhaustion
summary: >-
  stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy
  endpoint, allowing attackers to cause denial of service by memory exhaustion.
  Attackers can host malicious SVGs with extremely large width and height values
  an…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-400
published: '2026-08-16'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:06:30.133'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73057'
references:
  - url: >-
      https://github.com/stoatchat/stoatchat/security/advisories/GHSA-x87r-h3mq-7mgr
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/stoatchat-before-uncapped-svg-rendering-denial-of-service
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/stoatchat/stoatchat/security/advisories/GHSA-x87r-h3mq-7mgr
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00488
epssPercentile: 0.39321
ingestedAt: '2026-09-24T20:51:40.203Z'
---

## Overview

stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger concurrent requests to exhaust available memory across proxy replicas.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
