Description
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate decompressed archive entry sizes during file extraction which allows authenticated users with file upload permissions to cause a denial of service via crafted zip archives containing highly compressed entries (zip bombs) that exhaust server memory.. Mattermost Advisory ID: MMSA-2026-00598
Published: 2026-03-26
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Mattermost versions 11.4.x (up to 11.4.0), 11.3.x (up to 11.3.1), 11.2.x (up to 11.2.3), and 10.11.x (up to 10.11.11) fail to validate the size of decompressed archive entries during extraction. An authenticated user with permission to upload files can craft a zip archive that expands to an enormous size (zip bomb). On extraction the server consumes large amounts of memory, eventually crashing or becoming unresponsive, thereby causing a denial of service. The weakness is a failure to enforce size limits on incoming files.

Affected Systems

The vulnerability affects Mattermost Server installations running the listed versions. Specifically, all deployments of versions 11.4.0 or earlier, 11.3.1 or earlier, 11.2.3 or earlier, and 10.11.11 or earlier are impacted, regardless of the environment or operating system.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity and the EPSS score of less than 1% suggests that exploitation is unlikely in the near term. The vulnerability is not listed in the CISA KEV catalog. An attacker needs only an authenticated account with file upload permissions to trigger the denial of service; no elevated privileges are required. Once activated, the server consumes excessive memory during zip extraction, potentially causing the Mattermost service to crash or become unresponsive for all users. While this does not expose data or modify system state, the availability impact can disrupt business operations relying on the messaging platform. Consequently, the risk is moderate but present, especially in environments where file uploads are enabled and the application is not promptly patched.

Generated by OpenCVE AI on March 30, 2026 at 20:30 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.5.0, 11.4.1, 11.3.2, 11.2.4, 10.11.12 or higher.


OpenCVE Recommended Actions

  • Apply the Mattermost update to at least version 11.5.0 (or 10.11.12 for older releases) to fix the zip bomb denial of service vulnerability. If the update cannot be applied immediately, temporarily disable file upload capability or restrict it to essential users until the update is applied.

Generated by OpenCVE AI on March 30, 2026 at 20:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vhgh-g7x8-4rx8 Mattermost doesn't validate decompressed archive entry sizes during file extraction
References
History

Mon, 30 Mar 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost mattermost Server
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:11.4.0:*:*:*:*:*:*:*
Vendors & Products Mattermost mattermost Server

Fri, 27 Mar 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Thu, 26 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Mar 2026 16:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate decompressed archive entry sizes during file extraction which allows authenticated users with file upload permissions to cause a denial of service via crafted zip archives containing highly compressed entries (zip bombs) that exhaust server memory.. Mattermost Advisory ID: MMSA-2026-00598
Title Zip Bomb Denial of Service via Unrestricted Archive Decompression
Weaknesses CWE-409
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Mattermost Mattermost Mattermost Server
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-03-26T17:51:14.833Z

Reserved: 2026-02-24T11:01:47.197Z

Link: CVE-2026-3114

cve-icon Vulnrichment

Updated: 2026-03-26T17:47:26.384Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-26T17:16:42.480

Modified: 2026-03-30T19:40:45.843

Link: CVE-2026-3114

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-30T20:57:41Z

Weaknesses