Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a request path that includes user inputs which allows an attacker to cause excessive resource consumption, possibly leading to a DoS via sending large request paths
2024-04-26T09:15:11.880
2025-05-12T13:37:38.673
Analyzed
CVSSv3.1: 3.1 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mattermost | mattermost_server | < 8.1.12 | Yes |
Application | mattermost | mattermost_server | < 9.5.3 | Yes |
Application | mattermost | mattermost_server | < 9.6.1 | Yes |