Denial of Service Vulnerability in Mattermost Plugins by Mattermost
CVE-2026-24661
3.7LOW
What is CVE-2026-24661?
Mattermost Plugins versions up to and including 2.1.3.0 are vulnerable to a denial of service flaw due to insufficient request body size restrictions on the /changes webhook endpoint. An authenticated attacker could exploit this vulnerability by sending a large JSON payload, leading to memory exhaustion and service disruption. Users are advised to upgrade to the latest version to safeguard their systems.
Affected Version(s)
Mattermost 0 <= 2.1.3
Mattermost 2.3.2.0