Mattermost Denial-of-Service Vulnerability in Message Attachment Handling

Vulnerability

A denial-of-service vulnerability has been identified in Mattermost versions 11.7.x prior to 11.7.2, 11.6.x prior to 11.6.4, and 10.11.x prior to 10.11.19. The issue arises because these versions do not properly validate the length and content of message attachment field values. This flaw allows an authenticated attacker to disrupt service for all users in a channel by posting a message with a specially crafted payload that exploits catastrophic backtracking in the client-side markdown parser.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition for all users in the affected channel.

Remediation

Users can upgrade to Mattermost versions 11.8.0, 11.7.5, or 11.6.10 to address this vulnerability.

Added: Jul 13, 2026, 9:24 AM
Updated: Jul 13, 2026, 9:24 AM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
0.8
exploitability
5.2
remediation
7.7
relevance
9.3
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.