Executive brief
Mattermost, a collaboration and messaging platform, is affected by a vulnerability in its plugin system. An authorized user with high-level permissions can send excessively large requests to a specific web address (webhook) used by the system. This can overwhelm the server, causing the messaging service to become slow or completely unavailable for other employees.
Technical details
A resource consumption vulnerability (CWE-400) exists in Mattermost Plugins due to a failure to validate the size of incoming requests. An authenticated attacker with high privileges (PR:H) can exploit this by sending oversized payloads to the webhook endpoint. This lack of input validation leads to uncontrolled resource consumption, resulting in a denial-of-service (DoS) condition. The issue is addressed in versions 10.11.12, 11.2.4, 11.3.2, and 11.4.1.
Affected products
- Mattermost Mattermost Server 10.11.0 to 10.11.11, 11.2.0 to 11.2.3, 11.3.0 to 11.3.1, 11.4.0
Timeline
- 2026-03-26: disclosed: Initial disclosure by Mattermost
- 2026-03-26: advisory: NVD entry published