Loading market data...
← Back to CVE feed

CVE-2026-100678

MEDIUM CVSS 6.5 View on NVD ↗

Description

stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who know a password to guess TOTP codes with only IP-based rate limiting. Attackers can reuse MFA challenge tickets across multiple failed attempts and distribute guesses across IP addresses to bypass rate limiting and gain account access.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Published: Sep 26, 2026 14:16 UTC Modified: Sep 26, 2026 14:16 UTC