CVE-2026-100674
MEDIUMDescription
stoatchat before 0.15.5 fails to revalidate usernames after Unicode sanitization, allowing attackers to create usernames with forbidden characters by submitting Unicode letters that transform into rejected characters. Attackers can bypass character allowlists and length limits to create reserved-name lookalikes, embed special characters, and exceed the 32-character storage limit.
Is your site exposed to CVE-2026-100674?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2026-100674? +
How severe is CVE-2026-100674? +
How do I check if I'm vulnerable to CVE-2026-100674? +
Related Vulnerabilities
Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store a case-insensitive string value that violates …
`zip` is a zip library for rust which supports reading and writing of simple ZIP files. In the archive extraction …
go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed …
Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer Pentestify 1.2.0 through 2.3.2 allows an …
The cohttp package before 6.3.0 for OCaml allows directory traversal.
PeaZip before 11.3.0, in a non-default configuration, is vulnerable to OS command injection via a filename in an archive because …