File Upload Issues in Mattermost Leading to Resource Exhaustion
CVE-2026-11993

4.3MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
14 September 2026

What is CVE-2026-11993?

Certain versions of Mattermost are affected by a vulnerability that fails to properly enforce limits on the number of concurrent file uploads and manage failed file handling. This can lead to excessive resource usage as a user with upload permissions may continuously upload large files, which in turn spawns more goroutines than intended. This situation could significantly obstruct the indexing of other files, creating potential service disruptions.

Affected Version(s)

Mattermost 11.9.0

Mattermost 11.8.0 <= 11.8.4

Mattermost 11.7.0 <= 11.7.7

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

JG Heithcock
.