Mattermost Denial-of-Service Vulnerability via Outgoing Webhook Attachments

Vulnerability

A denial-of-service vulnerability has been identified in Mattermost versions 11.6.0, 11.5.3, 11.4.4, and 10.11.14. The issue arises because these versions do not properly filter nil elements from outgoing webhook attachment payloads before processing. This flaw allows an authenticated user to craft a webhook callback response with a null attachment entry, leading to the termination of the server process.

Impact

Exploitation of this vulnerability causes the Mattermost server process to terminate, leading to a denial-of-service condition.

Remediation

Users can upgrade to Mattermost versions 11.8.0 or 11.7.18 to address this vulnerability.

Added: May 26, 2026, 8:03 PM
Updated: May 26, 2026, 8:03 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
5.2
remediation
8.3
relevance
8.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.