Markdown Autolink Parsing Vulnerability in Mattermost by Mattermost
CVE-2026-12882
4.3MEDIUM
What is CVE-2026-12882?
An issue exists in Mattermost where certain versions improperly handle Markdown autolinks, particularly those with unmatched trailing closing parentheses. This flaw can be exploited by authenticated users with permissions to create posts, leading to excessive CPU utilization. The result may significantly impact the server's availability, affecting other users' ability to use the service. The vulnerability is documented in the Mattermost Advisory MMSA-2026-00703.
Affected Version(s)
Mattermost 11.9.0
Mattermost 11.8.0 <= 11.8.4
Mattermost 11.7.0 <= 11.7.7