Description
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit size of unpacked SDP messages compressed with zlib, which allows attacker to deny service or crash server via sending many SDP messages that unpack to large size.. Mattermost Advisory ID: MMSA-2026-00643
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via unbounded zlib decompression
Action: Patch Update
AI Analysis

Impact

Certain Mattermost server versions decompress Call SDP WebSocket messages without imposing a limit on the resulting uncompressed size. An attacker can craft numerous messages that, when decompressed, exceed the server’s memory or resource bounds, causing the server to consume excessive memory and ultimately crash or become unreachable. The weakness is a resource exhaustion flaw classified as CWE-409.

Affected Systems

Mattermost releases 11.9.x through 11.9.0, 11.8.x through 11.8.4, 11.7.x through 11.7.7, and 10.11.x through 10.11.22 are vulnerable. Any deployment of these versions that accepts SDP WebSocket traffic is at risk.

Risk and Exploitability

The CVSS base score of 6.5 indicates a medium severity according to NIST guidelines. EPSS data is unavailable, and the vulnerability is not listed in CISA’s KEV catalog, implying no publicly known exploits yet. However, because the attack requires sending crafted WebSocket payloads, an adversary who can reach the target network could repeatedly send large SDP messages to trigger a denial of service. The attack vector is inferred to be internal or remote network access to the Mattermost WebSocket endpoint, depending on exposure of that service.

Generated by OpenCVE AI on September 15, 2026 at 14:29 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or higher.


OpenCVE Recommended Actions

  • Update Mattermost to 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or newer
  • Ensure network traffic to the Mattermost WebSocket endpoint is protected by firewall rules that limit excessive inbound traffic
  • Apply system hardening practices such as enabling rate limiting on WebSocket connections and monitoring for unusual volume of SDP messages to detect abuse

Generated by OpenCVE AI on September 15, 2026 at 14:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Mon, 14 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit size of unpacked SDP messages compressed with zlib, which allows attacker to deny service or crash server via sending many SDP messages that unpack to large size.. Mattermost Advisory ID: MMSA-2026-00643
Title Unbounded zlib decompression in Calls SDP WebSocket messages
Weaknesses CWE-409
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-09-14T11:19:45.000Z

Reserved: 2026-03-30T09:58:00.256Z

Link: CVE-2026-5132

cve-icon Vulnrichment

Updated: 2026-09-14T11:13:33.270Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T11:17:04.140

Modified: 2026-09-16T19:30:49.967

Link: CVE-2026-5132

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:30:08Z

Weaknesses
  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)