Description
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22 fail to limit the nesting depth in the server-side Markdown parser which allows an authenticated attacker to cause a denial of service (CPU resource exhaustion) via a crafted post containing deeply nested blockquotes or list items.. Mattermost Advisory ID: MMSA-2026-00707
Published: 2026-09-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service by CPU exhaustion through unbounded Markdown nesting
Action: Patch
AI Analysis

Impact

Mattermost server processes user posts through a Markdown parser that fails to enforce a maximum nesting depth. An authenticated attacker can craft a post containing deeply nested blockquotes or list items, causing the parser to consume excessive CPU time and memory, ultimately leading to a denial of service. This is a classic resource exhaustion issue covered by CWE-407.

Affected Systems

The vulnerability affects Mattermost server releases 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22. Any instance running one of these versions and allowing authenticated users to submit posts is at risk.

Risk and Exploitability

With a CVSS score of 4.3 the vulnerability is of moderate severity. The EPSS score is not available and the weakness is not listed in the CISA KEV catalog. The attack vector requires an authenticated user who can create posts; the exploit path involves submitting a crafted post that triggers excessive recursive parsing, exhausting CPU resources. While exploitation probability cannot be precisely quantified, any authenticated attacker could leverage this to degrade service availability.

Generated by OpenCVE AI on September 15, 2026 at 14:20 UTC.

Remediation

Vendor Solution

Update Mattermost to versions 11.10.0, 11.9.1, 11.8.5, 11.7.9, 10.11.23 or higher.


OpenCVE Recommended Actions

  • Update Mattermost to version 11.10.0, 11.9.1, 11.8.5, 11.7.9, 10.11.23 or later, as advised by the vendor
  • If updating immediately is not possible, validate and sanitize post content client‑side or on the server to enforce a maximum Markdown nesting depth before processing
  • Implement application‑level monitoring to detect abnormal CPU usage patterns associated with Markdown parsing and throttle or block suspicious post submissions when thresholds are exceeded

Generated by OpenCVE AI on September 15, 2026 at 14:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22 fail to limit the nesting depth in the server-side Markdown parser which allows an authenticated attacker to cause a denial of service (CPU resource exhaustion) via a crafted post containing deeply nested blockquotes or list items.. Mattermost Advisory ID: MMSA-2026-00707
Title Mattermost Server Algorithmic DoS via Unbounded Markdown Block Nesting
Weaknesses CWE-407
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Mattermost Mattermost
cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-09-14T19:23:01.455Z

Reserved: 2026-09-07T09:38:22.768Z

Link: CVE-2026-86349

cve-icon Vulnrichment

Updated: 2026-09-14T19:15:30.809Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T14:17:15.687

Modified: 2026-09-16T19:30:49.967

Link: CVE-2026-86349

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:30:08Z

Weaknesses
  • CWE-407

    Inefficient Algorithmic Complexity