cbcvebase.
CVE-2025-14822
published 2026-01-16

CVE-2025-14822: Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources…

PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.32%
24.1th percentile
Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources via a single HTTP request containing a post with thousands space-separated tokens

Affected

6 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 10.11.0 < 10.11.910.11.9
github.commattermost_mattermost-server>= 10.11.0+incompatible < 10.11.9+incompatible10.11.9+incompatible
github.commattermost_mattermost-server>= 11.0.0 < 11.2.011.2.0
github.commattermost_mattermost-server>= 11.0.1+incompatible < 11.2.0+incompatible11.2.0+incompatible
mattermostmattermost10.11.0 – 10.11.8
mattermostmattermost_server>= 10.11.0 < 10.11.910.11.9
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.