Mattermost · Mattermost · CVE-2026-10600
**Name of the Vulnerable Software and Affected Versions**
Mattermost version 11.8.0
Mattermost version 11.7.3
Mattermost version 11.6.5
Mattermost version 10.11.20
**Description**
An issue exists where the server fails to bound the time and resource consumption during server-side document content extraction. An authenticated user with file-upload permissions can degrade file upload performance for all users on the server by repeatedly uploading small documents that are inexpensive to upload but resource-intensive to extract, which saturates the shared extraction worker pool.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.