Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit decompressed content size and enforce the configured maximum file size in the Boards archive import handler, which allows an authenticated user to cause memory exhaustion or unbounded disk consumption via a crafted .boardarchive file uploaded to the import endpoint.. Mattermost Advisory ID: MMSA-2026-00713
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-13 09:17
Updated : 2026-09-14 11:17
NVD link : CVE-2026-14298
Mitre link : CVE-2026-14298
CVE.ORG link : CVE-2026-14298
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)
