Impact
Certain Mattermost server versions decompress Call SDP WebSocket messages without imposing a limit on the resulting uncompressed size. An attacker can craft numerous messages that, when decompressed, exceed the server’s memory or resource bounds, causing the server to consume excessive memory and ultimately crash or become unreachable. The weakness is a resource exhaustion flaw classified as CWE-409.
Affected Systems
Mattermost releases 11.9.x through 11.9.0, 11.8.x through 11.8.4, 11.7.x through 11.7.7, and 10.11.x through 10.11.22 are vulnerable. Any deployment of these versions that accepts SDP WebSocket traffic is at risk.
Risk and Exploitability
The CVSS base score of 6.5 indicates a medium severity according to NIST guidelines. EPSS data is unavailable, and the vulnerability is not listed in CISA’s KEV catalog, implying no publicly known exploits yet. However, because the attack requires sending crafted WebSocket payloads, an adversary who can reach the target network could repeatedly send large SDP messages to trigger a denial of service. The attack vector is inferred to be internal or remote network access to the Mattermost WebSocket endpoint, depending on exposure of that service.
OpenCVE Enrichment