Impact
Mattermost versions 11.7.x, 11.6.x and 10.11.x that are older than the fixed releases fail to validate the length and content of message attachment field values. An authenticated user can embed a specially crafted payload that triggers catastrophic backtracking in the client‑side markdown parser, exhausting client resources and rendering the interface unresponsive for all users in a channel. The weakness is a regex backtracking issue, identified as CWE‑1333, which directly impacts application availability.
Affected Systems
The vulnerability affects Mattermost versions 10.11.0 to 10.11.19, 11.6.0 to 11.6.4, and 11.7.0 to 11.7.2. Any installation within these version ranges is susceptible; administrators should verify the installed release and plan a remediation upgrade.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity, and the exploitability is reasonable given the requirement for authentication and the presence of a crafted payload. Because the EPSS score of < 1%—approximately 0.24% based on the available value—indicates a very low but nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, the potential for channel‑wide denial of service is low. The attack occurs client‑side, so malicious content can be shared through normal posting mechanisms; an attacker in a channel can simply post the payload and cause a distributed service disruption for all users.
OpenCVE Enrichment