Server Performance Issues in Mattermost Product Line
CVE-2026-24458
7.5HIGH
What is CVE-2026-24458?
Certain versions of Mattermost are susceptible to a vulnerability that occurs due to inadequate handling of excessively long passwords. Attackers can exploit this flaw by submitting login attempts with passwords that are several megabytes in size, potentially overwhelming the server's CPU and memory resources. This can lead to significant performance degradation and impact the availability of the Mattermost service.
Affected Version(s)
Mattermost 11.3.0
Mattermost 11.2.0 <= 11.2.2
Mattermost 10.11.0 <= 10.11.10