Description
Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji.. Mattermost Advisory ID: MMSA-2026-00695
Published: 2026-07-27
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Mattermost versions in the 11.6.x, 10.11.x, 11.8.x, and 11.7.x series do not limit the number of frames in an animated GIF nor enforce the file size cap when that GIF is uploaded as a custom emoji. This oversight allows an attacker with permission to upload custom emojis to submit a specially crafted file that can exhaust server resources and disrupt the emoji upload process, causing a denial of service. The weakness is classified as CWE‑409, reflecting a failure to enforce a defined constraint on input data.

Affected Systems

Mattermost Server installations running any of the following releases are affected: 11.6.x up to and including 11.6.5, 10.11.x up to and including 10.11.20, 11.8.x up to and including 11.8.1, and 11.7.x up to and including 11.7.4.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a very low probability of exploitation today, and the vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated and have permission to upload custom emojis; once they submit an oversized or frame‑rich GIF, processing it drains server resources, leading to a denial of service for the emoji functionality and any users who interact with the emoji.

Generated by OpenCVE AI on August 4, 2026 at 13:56 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.9.0, 11.6.6, 10.11.21, 11.8.2, 11.7.5 or higher.


OpenCVE Recommended Actions

  • Upgrade Mattermost to at least version 11.9.0, 11.6.6, 10.11.21, 11.8.2, or 11.7.5 or newer as released by the vendor advisory.
  • If an immediate patch is not possible, temporarily disable the ability for users to upload custom emojis, ensuring that only pre‑existing emojis can be used.
  • Configure the server to enforce a stricter file size limit for uploads and block or restrict animated GIF processing in the upload workflow until the patch is applied.

Generated by OpenCVE AI on August 4, 2026 at 13:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 27 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji.. Mattermost Advisory ID: MMSA-2026-00695
Title Mattermost Server Denial of Service via Animated GIF Emoji Upload
Weaknesses CWE-409
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Mattermost Mattermost Mattermost Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-07-27T15:05:28.394Z

Reserved: 2026-06-04T07:34:33.428Z

Link: CVE-2026-10819

cve-icon Vulnrichment

Updated: 2026-07-27T15:05:23.347Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T15:16:46.770

Modified: 2026-08-03T15:23:50.490

Link: CVE-2026-10819

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T14:00:03Z

Weaknesses
  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)