Mattermost Vulnerability in Integration Action Endpoints
CVE-2026-2456
What is CVE-2026-2456?
The Mattermost application fails to restrict the size of responses from integration action endpoints, potentially allowing an authenticated attacker to exploit this weakness. By triggering an interaction through a malicious integration server that returns excessively large responses when a user activates an interactive message button, the attacker can lead to server memory exhaustion, resulting in denial of service for legitimate users. This poses a significant risk to service availability and overall platform performance.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mattermost 11.3.0
Mattermost 11.2.0 <= 11.2.2
Mattermost 10.11.0 <= 10.11.10
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved