Mattermost Denial-of-Service Vulnerability in Meetings API Endpoint

Vulnerability

A denial-of-service vulnerability has been identified in Mattermost versions 11.5.x through 11.5.1, 10.11.x through 10.11.13, and 11.4.x through 11.4.3. The issue arises because these versions do not properly limit the size of the request body for the start meeting API endpoint. This oversight allows authenticated attackers to cause resource exhaustion by sending oversized HTTP POST requests to the meetings API, leading to a denial of service.

Impact

Exploitation of this vulnerability can cause resource exhaustion, leading to a denial-of-service condition on the affected Mattermost server.

Remediation

Users can upgrade to Mattermost versions 11.7.0, 11.6.1, or 11.4.5 to address this vulnerability.

Added: May 18, 2026, 8:22 AM
Updated: May 18, 2026, 8:22 AM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
5.2
remediation
7.7
relevance
8.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.