Summary
CVE-2026-73057 is an uncontrolled resource consumption vulnerability (CWE-400) in stoatchat’s proxy service (January), affecting all versions before 0.15.0. The proxy endpoint fails to validate SVG viewBox dimensions before allocating memory to render fetched images, allowing a remote, unauthenticated attacker to exhaust server memory. The issue carries a CVSS v4.0 score of 8.7 (High); no authentication or user interaction is required to exploit it over the network.
Technical details
- Root cause: the proxy’s image-decoding logic reads SVG
viewBoxwidth/height values and passes them directly to memory allocation routines without any upper bound check. - Trigger conditions: an attacker hosts a crafted SVG file with extreme dimensions (e.g., 200000×200000, which can consume roughly 1.4 GB of RAM per request) and submits its URL to the proxy endpoint, which fetches and decodes it.
- Attack vector: network-based, unauthenticated; the proxy accepts arbitrary attacker-supplied URLs and downloads/decodes their content as images.
- Impact: sending multiple concurrent requests referencing such SVGs can exhaust available memory across all proxy replicas, resulting in denial of service.
Affected software
- stoatchat (January proxy service): all versions before 0.15.0
Severity
- CVSS v3.1 Base Score: 7.5 (High) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - CVSS v4.0 Score: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: upgrade stoatchat to version 0.15.0 or later, which caps SVG dimension values before allocating memory during image decoding in the proxy.
- If no patch can be applied immediately: restrict or monitor outbound proxy fetch requests, rate-limit or throttle concurrent proxy requests per client, and consider disabling or restricting the image-proxy endpoint until the fix is deployed.

