WebSocket Message Parsing Flaw in Mattermost Server by Mattermost
CVE-2026-5740
7.5HIGH
What is CVE-2026-5740?
The Mattermost Server contains a vulnerability in the way it validates msgpack-encoded WebSocket frames. Certain versions of the software fail to perform adequate checks before allocating memory, which permits unauthenticated remote attackers to manipulate server processes. By sending a specifically crafted binary WebSocket message to the public endpoint, attackers can trigger a server crash, potentially resulting in a complete outage for all users.
Affected Version(s)
Mattermost 11.6.0
Mattermost 11.5.0 <= 11.5.3
Mattermost 11.4.0 <= 11.4.4