CyberRota Analysis
AI-GeneratedMattermost versions up to 11.9.0, 11.8.4, 11.7.7, and 10.11.22 are vulnerable due to improper enforcement of concurrent file processing limits, allowing users with upload permissions to overwhelm the server by continuously uploading large files. This can lead to denial of service conditions, as the excessive goroutines can block the indexing of other files. Organizations using these Mattermost versions, particularly those with high file upload activity, should prioritize remediation to mitigate potential service disruptions.
Original NVD Description
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly enforce the limit of concurrent files being processed and handled failed files, which allows a user with permission to upload files to spawn more goroutines than intended and block the indexing of other files via uploading heavy files constantly to the server.. Mattermost Advisory ID: MMSA-2026-00696