CVE-2026-10600

Summary

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all users on the server via repeatedly uploading small documents that are cheap to upload but expensive to extract, saturating the shared extraction worker pool.. Mattermost Advisory ID: MMSA-2026-00694

Affected Software

VendorProductVersion RangeStatus
MattermostMattermost11.8.0 <= 11.8.0affected
MattermostMattermost11.7.0 <= 11.7.3affected
MattermostMattermost11.6.0 <= 11.6.5affected
MattermostMattermost10.11.0 <= 10.11.20affected
MattermostMattermost11.9.0unaffected
MattermostMattermost11.8.1unaffected
MattermostMattermost11.7.4unaffected
MattermostMattermost11.6.6unaffected
MattermostMattermost10.11.21unaffected

Weaknesses

  • CWE-770: CWE-770: Allocation of Resources Without Limits or Throttling

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References