cbcvebase.
CVE-2025-14822
published 2026-01-16

CVE-2025-14822: Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources…

medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources via a single HTTP request containing a post with thousands space-separated tokens

Affected

6 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 10.11.0 < 10.11.910.11.9
github.commattermost_mattermost-server>= 10.11.0+incompatible < 10.11.9+incompatible10.11.9+incompatible
github.commattermost_mattermost-server>= 11.0.0 < 11.2.011.2.0
github.commattermost_mattermost-server>= 11.0.1+incompatible < 11.2.0+incompatible11.2.0+incompatible
mattermostmattermost10.11.0 – 10.11.8
mattermostmattermost_server>= 10.11.0 < 10.11.910.11.9