PT-2026-96724 · Mattermost · Mattermost
CVE-2026-95666
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Mattermost versions 11.7.0 through 11.7.10
Mattermost versions 11.8.0 through 11.8.5
Mattermost versions 11.9.0 through 11.9.1
Mattermost versions 11.10.0 through 11.10.1
Description
An authenticated user can cause excessive database load by sending a crafted request to the bulk reactions endpoint. This occurs because the system fails to limit the length of the post ID array accepted by the endpoint
POST /api/v4/posts/ids/reactions.Recommendations
Update Mattermost versions 11.7.0 through 11.7.10 to a version newer than 11.7.10.
Update Mattermost versions 11.8.0 through 11.8.5 to a version newer than 11.8.5.
Update Mattermost versions 11.9.0 through 11.9.1 to a version newer than 11.9.1.
Update Mattermost versions 11.10.0 through 11.10.1 to a version newer than 11.10.1.
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mattermost