Impact
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, and 10.11.x <= 10.11.20 do not restrict the time or resources used during server‑side document content extraction. An authenticated user who has permission to upload files can exploit this by repeatedly uploading very small documents that are inexpensive to upload but costly to process. Each upload consumes extraction worker resources, and a sufficient volume of such uploads can saturate the shared extraction worker pool, causing legitimate file uploads to fail and preventing users from sending or receiving files, effectively degrading service availability.
Affected Systems
Mattermost Server is affected. Vulnerable releases are any 11.8.x version up to 11.8.0, any 11.7.x up to 11.7.3, any 11.6.x up to 11.6.5, and any 10.11.x up to 10.11.20.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, primarily affecting availability. The exploit requires authentication and file‑upload privileges, so the attacker must be a legitimate user of the system. The EPSS score of 0.00212 (<1%) indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited publicly known exploitation. Nonetheless, the ability to exhaust shared system resources makes it a credible risk, especially in environments with many concurrent users.
OpenCVE Enrichment