CVE-2026-24661
published 2026-04-09CVE-2026-24661: Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker to cause…
PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.31%
23.4th percentile
Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00611
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-plugin-msteams | >= 0 < 1.15.1-0.20260213190728-6fe4d295592e | 1.15.1-0.20260213190728-6fe4d295592e |
| mattermost | mattermost | < 2.3.2.0 | 2.3.2.0 |
| mattermost | mattermost | <= 2.1.3 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Mattermost MS Teams plugin doesn't limit the request body size on the /changes webhook endpoint
ghsa·2026-04-09
CVE-2026-24661 [MEDIUM] CWE-770 Mattermost MS Teams plugin doesn't limit the request body size on the /changes webhook endpoint
Mattermost MS Teams plugin doesn't limit the request body size on the /changes webhook endpoint
Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00611.
GHSA
GHSA-5rfv-h47g-xj42: Mattermost Plugins versions <=2
ghsa_unreviewed·2026-04-09
CVE-2026-24661 [LOW] CWE-770 GHSA-5rfv-h47g-xj42: Mattermost Plugins versions <=2
Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00611
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-09
Published