CVE-2026-2325
published 2026-05-18CVE-2026-2325: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to limit the size of the request body on the start meeting API endpoint, which…
PriorityP337medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.24%
15.2th percentile
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to limit the size of the request body on the start meeting API endpoint, which allows an authenticated attacker to cause resource exhaustion or denial of service via a crafted oversized HTTP POST request to {{/api/v1/meetings}}.. Mattermost Advisory ID: MMSA-2026-00608
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-plugin-msteams-meetings | >= 0 < 1.1.1-0.20260213105619-c5892dd169de | 1.1.1-0.20260213105619-c5892dd169de |
| github.com | mattermost_mattermost-server | >= 10.11.0 < 10.11.14 | 10.11.14 |
| github.com | mattermost_mattermost-server | >= 11.4.0 < 11.4.4 | 11.4.4 |
| github.com | mattermost_mattermost-server | >= 11.5.0 < 11.5.2 | 11.5.2 |
| mattermost | mattermost | 10.11.0 – 10.11.13 | — |
| mattermost | mattermost | 11.4.0 – 11.4.3 | — |
| mattermost | mattermost | 11.5.0 – 11.5.1 | — |
| mattermost | mattermost_server | >= 10.11.0 < 10.11.14 | 10.11.14 |
| mattermost | mattermost_server | >= 11.4.0 < 11.4.4 | 11.4.4 |
| mattermost | mattermost_server | >= 11.5.0 < 11.5.2 | 11.5.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m3p3-8frq-q7qh: Mattermost versions 11
ghsa_unreviewed·2026-05-18
CVE-2026-2325 [MEDIUM] CWE-770 GHSA-m3p3-8frq-q7qh: Mattermost versions 11
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to limit the size of the request body on the start meeting API endpoint, which allows an authenticated attacker to cause resource exhaustion or denial of service via a crafted oversized HTTP POST request to {{/api/v1/meetings}}.. Mattermost Advisory ID: MMSA-2026-00608
GHSA
Mattermost doesn't limit the size of the request body on the start meeting API endpoint
ghsa·2026-05-18
CVE-2026-2325 [MEDIUM] CWE-770 Mattermost doesn't limit the size of the request body on the start meeting API endpoint
Mattermost doesn't limit the size of the request body on the start meeting API endpoint
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to limit the size of the request body on the start meeting API endpoint, which allows an authenticated attacker to cause resource exhaustion or denial of service via a crafted oversized HTTP POST request to {{/api/v1/meetings}}.. Mattermost Advisory ID: MMSA-2026-00608
VulDB
Mattermost up to 10.11.13/11.4.3/11.5.1 Start Meeting API Endpoint /api/v1/meetings request body allocation of resources
vuldb·2026-05-18·CVSS 6.5
CVE-2026-2325 [MEDIUM] Mattermost up to 10.11.13/11.4.3/11.5.1 Start Meeting API Endpoint /api/v1/meetings request body allocation of resources
A vulnerability was found in Mattermost up to 10.11.13/11.4.3/11.5.1. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the file /api/v1/meetings of the component Start Meeting API Endpoint. This manipulation of the argument request body causes allocation of resources.
This vulnerability is handled as CVE-2026-2325. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-18
Published