Description
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to prevent rendering of external SVGs on link embeds which allows unauthenticated users to crash the Mattermost webapp and desktop app via creating an issue or PR on GitHub.. Mattermost Advisory ID: MMSA-2026-00595
Published: 2026-03-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Mattermost versions from 10.11.0 to 11.4.0 allow unauthenticated users to trigger a denial of service by embedding external SVG images in link previews, causing the web and desktop applications to crash due to improper handling of such content. This vulnerability stems from a flaw that fails to block rendering of external SVG files, leading to application instability and service interruption. The weakness is identified as CWE‑754, involving improper release of resources.

Affected Systems

The affected product is Mattermost Server. Versions 11.4.x up to and including 11.4.0, 11.3.x up to 11.3.1, 11.2.x up to 11.2.3, and 10.11.x up to 10.11.11 are vulnerable. All installations of Mattermost older than 11.5.0, 11.4.1, 11.3.2, 11.2.4, or 10.11.12 must be updated to address the issue.

Risk and Exploitability

The vulnerability carries a CVSS base score of 4.3, indicating low to medium severity, and an EPSS estimate below 1%, suggesting a low probability of widespread exploitation. It is not listed in CISA’s KEV catalog. The attack vector is inferred to be unauthenticated users accessing link previews containing malicious external SVGs, which can be triggered simply by creating or viewing issues or pull requests that reference such content. Attackers do not need privileged access; the crash can deny service to all users of a Mattermost instance.

Generated by OpenCVE AI on March 26, 2026 at 20:55 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.5.0, 11.4.1, 11.3.2, 11.2.4, 10.11.12 or higher.


OpenCVE Recommended Actions

  • Update Mattermost to a patched version (11.5.0, 11.4.1, 11.3.2, 11.2.4, or 10.11.12 and later).
  • Verify that the update has been applied by checking application logs for crash events.

Generated by OpenCVE AI on March 26, 2026 at 20:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-86vc-mg26-fj6x Mattermost: Authenticated DoS through failure to prevent rendering of external SVGs on link embeds
References
History

Thu, 26 Mar 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost mattermost Server
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost mattermost Server

Thu, 26 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Wed, 25 Mar 2026 16:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to prevent rendering of external SVGs on link embeds which allows unauthenticated users to crash the Mattermost webapp and desktop app via creating an issue or PR on GitHub.. Mattermost Advisory ID: MMSA-2026-00595
Title DoS via URL Previews Rendering Malicious SVGs
Weaknesses CWE-754
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Mattermost Mattermost Mattermost Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-03-26T17:11:21.474Z

Reserved: 2026-02-23T22:07:32.817Z

Link: CVE-2026-20719

cve-icon Vulnrichment

Updated: 2026-03-26T17:11:18.760Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-25T17:16:30.307

Modified: 2026-03-26T18:54:18.977

Link: CVE-2026-20719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-27T09:30:32Z

Weaknesses