Denial of Service Vulnerability in Mattermost by Mattermost
CVE-2026-5755
6.5MEDIUM
What is CVE-2026-5755?
A vulnerability exists in certain versions of Mattermost due to improper validation of the TIFF IFD offset in the image headers, which can lead to a denial of service condition. Authenticated users who have file upload or posting permissions can exploit this flaw by uploading a specially crafted TIFF file or sharing a URL that serves such a file. This exploitation can result in excessive memory allocation, causing the server to run out of memory and become unresponsive.
Affected Version(s)
Mattermost 11.6.0
Mattermost 11.5.0 <= 11.5.2
Mattermost 11.5.0 <= 11.5.3