Server Crash Vulnerability in Mattermost Versions by Mattermost
CVE-2025-8402

4.9MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
21 August 2025

What is CVE-2025-8402?

Certain versions of Mattermost contain a flaw in their bulk import feature, which fails to properly validate import data. This vulnerability can be exploited by a system administrator to intentionally cause a server crash, leading to downtime and loss of service availability. The affected versions include 10.8.x up to 10.8.3, 10.5.x up to 10.5.8, 9.11.x up to 9.11.17, 10.10.x up to 10.10.0, and 10.9.x up to 10.9.3. To mitigate this issue, administrators should ensure their Mattermost installations are updated to the latest secure versions.

Affected Version(s)

Mattermost 10.8.0 <= 10.8.3

Mattermost 10.5.0 <= 10.5.8

Mattermost 9.11.0 <= 9.11.17

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daw10
.
CVE-2025-8402 : Server Crash Vulnerability in Mattermost Versions by Mattermost