Junglewise Threat Intelligence

CVE-2026-3116: Mattermost Plugins resource consumption via webhook endpoint

CVE-2026-3116 · Severity: medium · CVSS 4.9 · Published 2026-03-26

Technologies: Mattermost Server. Vendors: Mattermost.

Executive brief

Mattermost, a collaboration and messaging platform, is affected by a vulnerability in its plugin system. An authorized user with high-level permissions can send excessively large requests to a specific web address (webhook) used by the system. This can overwhelm the server, causing the messaging service to become slow or completely unavailable for other employees.

Technical details

A resource consumption vulnerability (CWE-400) exists in Mattermost Plugins due to a failure to validate the size of incoming requests. An authenticated attacker with high privileges (PR:H) can exploit this by sending oversized payloads to the webhook endpoint. This lack of input validation leads to uncontrolled resource consumption, resulting in a denial-of-service (DoS) condition. The issue is addressed in versions 10.11.12, 11.2.4, 11.3.2, and 11.4.1.

Affected products

  • Mattermost Mattermost Server 10.11.0 to 10.11.11, 11.2.0 to 11.2.3, 11.3.0 to 11.3.1, 11.4.0

Timeline

  • 2026-03-26: disclosed: Initial disclosure by Mattermost
  • 2026-03-26: advisory: NVD entry published

References

Related threats