VYPR
Medium severity4.3NVD Advisory· Published Jun 2, 2022· Updated Jun 17, 2026

CVE-2022-1982

CVE-2022-1982

Description

Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG attachment on a post.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/mattermost/mattermost-serverGo
>= 6.6.0, < 6.6.16.6.1
github.com/mattermost/mattermost-serverGo
>= 6.5.0, < 6.5.16.5.1
github.com/mattermost/mattermost-serverGo
>= 6.4.0, < 6.4.36.4.3
github.com/mattermost/mattermost-serverGo
>= 5.0.0, < 6.3.86.3.8

Affected products

6
  • cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*range: >=5.0.0,<6.3.8
    • cpe:2.3:a:mattermost:mattermost_server:6.5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mattermost:mattermost_server:6.6.0:*:*:*:*:*:*:*
    • (no CPE)range: 6.5.x 6.5.0
  • osv-coords2 versions
    >= 5.0.0, < 6.3.8+ 1 more
    • (no CPE)range: >= 5.0.0, < 6.3.8
    • (no CPE)range: >= 6.6.0, < 6.6.1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.