Memory Exhaustion Vulnerability in Mattermost Boards Archive Import Handler
CVE-2026-14298
6.5MEDIUM
What is CVE-2026-14298?
The Mattermost Boards archive import handler is susceptible to a memory exhaustion vulnerability due to inadequate limits on decompressed content size. This flaw enables authenticated users to exploit it by uploading a specially crafted .boardarchive file, potentially leading to unbounded disk consumption and memory exhaustion. This can hinder the application's functionality and lead to severe performance issues, especially in environments handling large files.
Affected Version(s)
Mattermost 11.9.0
Mattermost 11.8.0 <= 11.8.4
Mattermost 11.7.0 <= 11.7.7