Junglewise Threat Intelligence

CVE-2026-10600: Mattermost resource exhaustion in document content extraction

CVE-2026-10600 · Severity: medium · CVSS 4.3 · Published 2026-07-27

Technologies: Mattermost. Vendors: Mattermost.

Executive brief

Mattermost is a collaboration platform used for team communication and file sharing. A vulnerability in how the server processes uploaded documents allows a malicious user to slow down or block file uploads for everyone else on the server. By repeatedly uploading specially crafted small files that are difficult for the server to process, an attacker can exhaust the system's resources, leading to a partial service disruption.

Technical details

The vulnerability is classified as CWE-770 (Allocation of Resources Without Limits or Throttling) within the server-side document content extraction component. An authenticated attacker with file-upload permissions can exploit this by repeatedly uploading small documents that are computationally expensive to extract. This activity saturates the shared extraction worker pool, leading to a denial-of-service (DoS) condition specifically affecting the file upload functionality for all users. The issue is resolved in Mattermost versions 11.9.0, 11.8.1, 11.7.4, 11.6.6, and 10.11.21.

Affected products

  • Mattermost Mattermost 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20

Timeline

  • 2026-07-27: advisory: MMSA-2026-00694 published by Mattermost
  • 2026-07-27: disclosed: CVE-2026-10600 published to NVD

References

Related threats