Impact
Mattermost servers up to versions 10.11.22, 11.7.7, 11.8.4 and 11.9.0 fail to limit memory allocated during image decoding, allowing an authenticated user to upload a specially crafted image that triggers excessive memory consumption. The vulnerability is a classic uncontrolled memory allocation flaw (CWE‑409) that can saturate server resources, degrade performance, or cause a crash, thereby denying legitimate users access to the platform.
Affected Systems
The affected product is Mattermost. Versions vulnerable include 10.11.x up to 10.11.22, 11.7.x up to 11.7.7, 11.8.x up to 11.8.4, and 11.9.x up to 11.9.0. Updates to 10.11.23, 11.7.8, 11.8.5, 11.9.1, or newer 11.10.0 address the issue.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in KEV, suggesting limited public exploitation evidence. Exploit requires an authenticated user to upload a malicious image as a profile picture, channel attachment, team icon, or brand image. Therefore, the primary attack vector is through normal user upload channels, and adequate authentication controls mean that internal or compromised accounts can trigger the denial of service.
OpenCVE Enrichment