CVE-2026-15814

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit the amount of memory allocated when decoding uploaded image files which allows an authenticated user to cause excessive server memory consumption and potential denial of service via uploading a specially crafted image as a profile picture, channel file attachment, team icon, or custom brand image. Mattermost Advisory ID: MMSA-2026-00719
References
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-14 11:17

Updated : 2026-09-16 19:30


NVD link : CVE-2026-15814

Mitre link : CVE-2026-15814

CVE.ORG link : CVE-2026-15814


JSON object : View

Products Affected

No product.

CWE
CWE-409

Improper Handling of Highly Compressed Data (Data Amplification)