Description
Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF validation of plugin requests which allows an authenticated user to exhaust server memory and cause a denial of service via a large request body sent to a plugin endpoint.. Mattermost Advisory ID: MMSA-2026-00775
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update Mattermost to versions 11.11.0, 11.9.2, 11.8.6, 11.7.11, 11.10.2 or higher.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Tue, 22 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF validation of plugin requests which allows an authenticated user to exhaust server memory and cause a denial of service via a large request body sent to a plugin endpoint.. Mattermost Advisory ID: MMSA-2026-00775 | |
| Title | Mattermost server missing request body size limit on plugin routes allows denial of service by an authenticated user | |
| Weaknesses | CWE-789 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-09-22T20:34:49.141Z
Reserved: 2026-09-22T20:00:26.276Z
Link: CVE-2026-96260
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses