Request Body Handling Flaw in Mattermost Confluence Plugin
CVE-2025-54525
7.5HIGH
Key Information:
- Vendor
Mattermost
- Vendor
- CVE Published:
- 11 August 2025
What is CVE-2025-54525?
The Mattermost Confluence Plugin, specifically versions prior to 1.5.0, contains a flaw in its handling of unexpected request bodies. This vulnerability allows attackers to repeatedly target the channel subscription endpoint with malformed requests, ultimately leading to a crash of the plugin. Such exploitation can undermine the operating stability of the system, impacting user access and overall functionality.
Affected Version(s)
Mattermost Confluence Plugin 0 < 1.5.0
Mattermost Confluence Plugin 1.5.0