CyberRota Analysis
AI-GeneratedCertain versions of Mattermost are vulnerable to a denial of service due to inadequate restrictions on animated GIF uploads, allowing authenticated attackers to exploit this by uploading malicious files as custom emojis. This could lead to service disruptions, impacting user experience and system availability. Organizations using affected Mattermost versions should prioritize patching to mitigate potential service interruptions.
Original NVD Description
Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji.. Mattermost Advisory ID: MMSA-2026-00695
Related CVEs
Other vulnerabilities affecting the same vendor(s)