Impact
The vulnerability is a denial‑of‑service (DoS) caused by a failure to properly validate User‑Agent header tokens. An authenticated attacker can trigger a request panic by sending a specially crafted User‑Agent header, leading to service interruption. The underlying weakness is classified as CWE‑1287.
Affected Systems
Affected systems include Mattermost server versions 11.3.x up to 11.3.0, 11.2.x up to 11.2.2, and 10.11.x up to 10.11.10. Any installation running these versions with authenticated user access is vulnerable.
Risk and Exploitability
The CVSS score is 4.3, indicating low severity, and the EPSS score is below 1%, meaning exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user, so a legitimate account with permissions to make a request is needed. Although the risk is low, patching is recommended to prevent potential service interruption.
OpenCVE Enrichment
Github GHSA