Mattermost Denial-of-Service Vulnerability in API Request Handlers

Vulnerability

A denial-of-service vulnerability has been identified in Mattermost versions 11.6.0, 11.5.3, 11.4.4, and 10.11.14. The issue arises from the failure to properly validate user input in API request handlers, allowing an authenticated attacker to crash the plugin process. This can be achieved by sending a crafted HTTP request to the PR details endpoint.

Impact

Exploitation of this vulnerability leads to a crash of the plugin process, causing a denial-of-service condition.

Remediation

Users can upgrade to Mattermost versions 11.8.0 or 11.7.18 to address this vulnerability.

Added: May 26, 2026, 4:20 PM
Updated: May 26, 2026, 4:20 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.6
exploitability
5.2
remediation
8.3
relevance
9.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.