Denial of Service Vulnerability in Mattermost Plugins by Mattermost
CVE-2026-21388

3.7LOW

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
9 April 2026

What is CVE-2026-21388?

Mattermost Plugins versions up to and including 2.3.1 are susceptible to a vulnerability that allows authenticated users to exploit the {{/lifecycle}} webhook endpoint. By sending an excessively large JSON payload, an attacker can induce memory exhaustion, leading to a denial of service. This vulnerability emphasizes the importance of input validation and payload size restrictions in webhooks, potentially risking service availability.

Affected Version(s)

Mattermost 0 <= 2.3.1

Mattermost 2.3.2.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lorenzo Gallegos
.