Junglewise Threat Intelligence

CVE-2026-10819: Mattermost denial of service via animated GIF emoji uploads

CVE-2026-10819 · Severity: medium · CVSS 6.5 · Published 2026-07-27

Technologies: Mattermost Server. Vendors: Mattermost.

Executive brief

Mattermost, a collaboration and messaging platform, is vulnerable to a denial-of-service attack through its custom emoji feature. An authenticated user can upload a specially crafted animated GIF that bypasses file size and frame limits, potentially crashing the service or making it unresponsive for other users. This could disrupt business communications and team operations until the malicious file is removed or the service is restored.

Technical details

A denial-of-service (DoS) vulnerability exists in Mattermost Server due to improper handling of highly compressed data (CWE-409) during the processing of animated GIF uploads. The application fails to validate the number of frames or enforce file size restrictions when a user uploads a GIF for use as a custom emoji. An authenticated attacker can exploit this by uploading a crafted GIF designed to consume excessive system resources (CPU/Memory) during processing or rendering. The vulnerability is reachable over the network and requires basic user privileges. Patches are available in versions 10.11.21, 11.6.6, 11.7.5, 11.8.2, and 11.9.0.

Affected products

  • Mattermost Mattermost Server 10.11.0 - 10.11.20, 11.6.0 - 11.6.5, 11.7.0 - 11.7.4, 11.8.0 - 11.8.1

Timeline

  • 2026-07-27: advisory: MMSA-2026-00695 published by Mattermost
  • 2026-07-27: disclosed: CVE-2026-10819 published to NVD

References

Related threats