Denial of Service Vulnerability in Mattermost Plugins by Mattermost
CVE-2026-24661

3.7LOW

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
9 April 2026

What is CVE-2026-24661?

Mattermost Plugins versions up to and including 2.1.3.0 are vulnerable to a denial of service flaw due to insufficient request body size restrictions on the /changes webhook endpoint. An authenticated attacker could exploit this vulnerability by sending a large JSON payload, leading to memory exhaustion and service disruption. Users are advised to upgrade to the latest version to safeguard their systems.

Affected Version(s)

Mattermost 0 <= 2.1.3

Mattermost 2.3.2.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lorenzo Gallegos
.