Denial of Service Vulnerability in Mattermost by Mattermost Inc.
CVE-2026-5132

6.5MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
14 September 2026

What is CVE-2026-5132?

Certain versions of Mattermost contain a vulnerability that fails to restrict the size of unpacked SDP messages that are compressed with zlib. This oversight enables potential attackers to send numerous SDP messages that, when unpacked, can require excessive server resources, ultimately leading to a denial of service or even causing the server to crash. This vulnerability affects multiple versions of the product, underscoring the importance of timely updates and security practices.

Affected Version(s)

Mattermost 11.9.0

Mattermost 11.8.0 <= 11.8.4

Mattermost 11.7.0 <= 11.7.7

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daw10
.