Subscriptions
No data.
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
Update Mattermost to versions 11.5.0, 11.4.1, 11.3.2, 11.2.4, 10.11.12 or higher.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Thu, 26 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Mar 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate decompressed archive entry sizes during file extraction which allows authenticated users with file upload permissions to cause a denial of service via crafted zip archives containing highly compressed entries (zip bombs) that exhaust server memory.. Mattermost Advisory ID: MMSA-2026-00598 | |
| Title | Zip Bomb Denial of Service via Unrestricted Archive Decompression | |
| Weaknesses | CWE-409 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2026-03-26T17:51:14.833Z
Reserved: 2026-02-24T11:01:47.197Z
Link: CVE-2026-3114
Updated: 2026-03-26T17:47:26.384Z
Status : Received
Published: 2026-03-26T17:16:42.480
Modified: 2026-03-26T17:16:42.480
Link: CVE-2026-3114
No data.
OpenCVE Enrichment
No data.