CVE-2025-54463
published 2025-08-11CVE-2025-54463: Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.29%
21.3th percentile
Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to server webhook endpoint with an invalid request body.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-plugin-confluence | >= 0 < 1.5.0 | 1.5.0 |
| mattermost | confluence | < 1.5.0 | 1.5.0 |
| mattermost | mattermost_confluence_plugin | < 1.5.0 | 1.5.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost Confluence Plugin has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-plugin-confluence
osv·2025-08-18
CVE-2025-54463 Mattermost Confluence Plugin has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-plugin-confluence
Mattermost Confluence Plugin has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-plugin-confluence
Mattermost Confluence Plugin has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-plugin-confluence
OSV
Mattermost Confluence Plugin has Improper Check for Unusual or Exceptional Conditions
osv·2025-08-11
CVE-2025-54463 [MEDIUM] Mattermost Confluence Plugin has Improper Check for Unusual or Exceptional Conditions
Mattermost Confluence Plugin has Improper Check for Unusual or Exceptional Conditions
Mattermost Confluence Plugin versions < 1.5.0 fails to handle unexpected request bodies, allowing attackers to crash the plugin via constant hits to the server webhook endpoint with an invalid request body.
GHSA
Mattermost Confluence Plugin has Improper Check for Unusual or Exceptional Conditions
ghsa·2025-08-11
CVE-2025-54463 [MEDIUM] CWE-754 Mattermost Confluence Plugin has Improper Check for Unusual or Exceptional Conditions
Mattermost Confluence Plugin has Improper Check for Unusual or Exceptional Conditions
Mattermost Confluence Plugin versions < 1.5.0 fails to handle unexpected request bodies, allowing attackers to crash the plugin via constant hits to the server webhook endpoint with an invalid request body.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-11
Published