Mattermost Denial-of-Service Vulnerability via Malicious 7zip Archive

Vulnerability

A denial-of-service vulnerability has been identified in Mattermost versions 11.5.x through 11.5.1, 10.11.x through 10.11.13, and 11.4.x through 11.4.3. The issue arises because these versions do not properly validate the structure of 7zip archives before processing them. This flaw allows an authenticated attacker to upload a specially crafted 7zip file containing excessive folder declarations, leading to server memory exhaustion and causing a denial-of-service condition.

Impact

Exploitation of this vulnerability leads to server memory exhaustion, causing a denial-of-service condition.

Remediation

Users can upgrade to Mattermost versions 11.7.0, 11.6.1, or 10.11.15 to address this vulnerability.

Added: May 18, 2026, 8:20 AM
Updated: May 18, 2026, 8:20 AM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
5.2
remediation
7.7
relevance
8.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.