Server-Side Resource Exhaustion in Mattermost Affects Document Uploads
CVE-2026-10600
4.3MEDIUM
What is CVE-2026-10600?
In Mattermost, versions 11.8.x up to 11.8.0, 11.7.x up to 11.7.3, 11.6.x up to 11.6.5, and 10.11.x up to 10.11.20, a vulnerability exists in the handling of document uploads. Authenticated users with file-upload permissions can exploit this flaw by repeatedly uploading small documents, which are inexpensive to upload but costly to process. This behavior can exhaust the server’s resources by saturating the shared extraction worker pool, leading to performance degradation for all users. For more information, refer to the advisory MMSA-2026-00694.
Affected Version(s)
Mattermost 11.8.0
Mattermost 11.7.0 <= 11.7.3
Mattermost 11.6.0 <= 11.6.5