Junglewise Threat Intelligence

CVE-2026-5740: Mattermost Server denial of service via msgpack WebSocket frames

CVE-2026-5740 · Severity: high · CVSS 7.5 · Published 2026-05-22

Technologies: github.com/mattermost/mattermost-server/v5 (Go), github.com/mattermost/mattermost-server/v6 (Go), Mattermost Server, github.com/mattermost/mattermost/server/v8 (Go), github.com/mattermost/mattermost-server (Go). Vendors: Go, Mattermost.

Executive brief

Mattermost, a popular collaboration and messaging platform, is vulnerable to a flaw that allows an attacker to crash the server. By sending a specially crafted message to the server's public communication channel, an unauthenticated user can force the system to shut down. This results in a total service outage, preventing all employees from communicating until the server is manually restarted.

Technical details

A vulnerability exists in Mattermost Server's handling of WebSocket communications. The application fails to properly validate the size or structure of msgpack-encoded WebSocket frames before attempting to allocate memory for them (CWE-789). An unauthenticated remote attacker can exploit this by sending a crafted binary WebSocket message to the public WebSocket endpoint. This leads to excessive memory allocation, causing the server process to crash and resulting in a denial-of-service (DoS) condition. The issue is resolved in versions 11.7.0, 11.6.1, 11.5.4, 11.4.5, and 10.11.15.

Affected products

  • Mattermost Mattermost Server 11.6.0, 11.5.0 to 11.5.3, 11.4.0 to 11.4.4, 10.11.0 to 10.11.14

Timeline

  • 2026-05-22: advisory: Mattermost published advisory MMSA-2026-00647
  • 2026-05-22: disclosed: CVE-2026-5740 published to NVD

References

Related threats