Impact
Mattermost server processes user posts through a Markdown parser that fails to enforce a maximum nesting depth. An authenticated attacker can craft a post containing deeply nested blockquotes or list items, causing the parser to consume excessive CPU time and memory, ultimately leading to a denial of service. This is a classic resource exhaustion issue covered by CWE-407.
Affected Systems
The vulnerability affects Mattermost server releases 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22. Any instance running one of these versions and allowing authenticated users to submit posts is at risk.
Risk and Exploitability
With a CVSS score of 4.3 the vulnerability is of moderate severity. The EPSS score is not available and the weakness is not listed in the CISA KEV catalog. The attack vector requires an authenticated user who can create posts; the exploit path involves submitting a crafted post that triggers excessive recursive parsing, exhausting CPU resources. While exploitation probability cannot be precisely quantified, any authenticated attacker could leverage this to degrade service availability.
OpenCVE Enrichment