Description
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit the amount of memory allocated when decoding uploaded image files which allows an authenticated user to cause excessive server memory consumption and potential denial of service via uploading a specially crafted image as a profile picture, channel file attachment, team icon, or custom brand image. Mattermost Advisory ID: MMSA-2026-00719
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

Mattermost servers up to versions 10.11.22, 11.7.7, 11.8.4 and 11.9.0 fail to limit memory allocated during image decoding, allowing an authenticated user to upload a specially crafted image that triggers excessive memory consumption. The vulnerability is a classic uncontrolled memory allocation flaw (CWE‑409) that can saturate server resources, degrade performance, or cause a crash, thereby denying legitimate users access to the platform.

Affected Systems

The affected product is Mattermost. Versions vulnerable include 10.11.x up to 10.11.22, 11.7.x up to 11.7.7, 11.8.x up to 11.8.4, and 11.9.x up to 11.9.0. Updates to 10.11.23, 11.7.8, 11.8.5, 11.9.1, or newer 11.10.0 address the issue.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in KEV, suggesting limited public exploitation evidence. Exploit requires an authenticated user to upload a malicious image as a profile picture, channel attachment, team icon, or brand image. Therefore, the primary attack vector is through normal user upload channels, and adequate authentication controls mean that internal or compromised accounts can trigger the denial of service.

Generated by OpenCVE AI on September 15, 2026 at 14:30 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or higher.


OpenCVE Recommended Actions

  • Update Mattermost to a supported version that includes the patch, such as 10.11.23, 11.7.8, 11.8.5, 11.9.1, or 11.10.0 or higher.
  • If an immediate upgrade is not feasible, implement temporary controls to limit or block large or suspicious image uploads—disable custom avatar, channel file attachment, team icon, or brand image uploads, or apply file size restrictions via network or application firewall.
  • Monitor server memory usage and audit upload logs for abnormal activity to detect exploitation attempts.

Generated by OpenCVE AI on September 15, 2026 at 14:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 14 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit the amount of memory allocated when decoding uploaded image files which allows an authenticated user to cause excessive server memory consumption and potential denial of service via uploading a specially crafted image as a profile picture, channel file attachment, team icon, or custom brand image. Mattermost Advisory ID: MMSA-2026-00719
Title Uploading a crafted image causes excessive memory allocation in the Mattermost Server
Weaknesses CWE-409
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-09-14T11:19:45.210Z

Reserved: 2026-07-15T10:53:51.646Z

Link: CVE-2026-15814

cve-icon Vulnrichment

Updated: 2026-09-14T11:13:35.352Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T11:17:03.697

Modified: 2026-09-16T19:30:49.967

Link: CVE-2026-15814

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:30:08Z

Weaknesses
  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)