Unrated severityNVD Advisory· Published Jul 27, 2026· Updated Jul 27, 2026
Denial of service via unbounded document content extraction in Mattermost Server
CVE-2026-10600
Description
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all users on the server via repeatedly uploading small documents that are cheap to upload but expensive to extract, saturating the shared extraction worker pool.. Mattermost Advisory ID: MMSA-2026-00694
Affected products
1- Range: <=11.8.0, <=11.7.3, <=11.6.5, <=10.11.20
Patches
Vulnerability mechanics
References
1- mattermost.com/security-updatesmitrevendor-advisory
News mentions
0No linked articles in our index yet.