CVE-2026-96260
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Summary
Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF validation of plugin requests which allows an authenticated user to exhaust server memory and cause a denial of service via a large request body sent to a plugin endpoint.. Mattermost Advisory ID: MMSA-2026-00775
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Mattermost | Mattermost | 11.9.0 <= 11.9.1 | affected |
| Mattermost | Mattermost | 11.8.0 <= 11.8.5 | affected |
| Mattermost | Mattermost | 11.7.0 <= 11.7.10 | affected |
| Mattermost | Mattermost | 11.10.0 <= 11.10.1 | affected |
| Mattermost | Mattermost | 11.11.0 | unaffected |
| Mattermost | Mattermost | 11.9.2 | unaffected |
| Mattermost | Mattermost | 11.8.6 | unaffected |
| Mattermost | Mattermost | 11.7.11 | unaffected |
| Mattermost | Mattermost | 11.10.2 | unaffected |
Weaknesses
- CWE-789: CWE-789: Memory Allocation with Excessive Size Value
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.