CVE-2026-6333
published 2026-05-18CVE-2026-6333: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response URLs for custom slash commands which…
PriorityP429medium5CVSS 3.1
AVNACLPRLUINSCCNILAN
EPSS
0.14%
3.5th percentile
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response URLs for custom slash commands which allows an authenticated attacker to redirect slash command responses to an attacker-controlled server via a spoofed Host header.. Mattermost Advisory ID: MMSA-2026-00582
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 0 < 5.3.2-0.20260325160634-e738016c5920 | 5.3.2-0.20260325160634-e738016c5920 |
| github.com | mattermost_mattermost_server_v8 | >= 0 < 8.0.0-20260325160634-e738016c5920 | 8.0.0-20260325160634-e738016c5920 |
| github.com | mattermost_mattermost_server_v8 | >= 10.11.0 < 10.11.14 | 10.11.14 |
| github.com | mattermost_mattermost_server_v8 | >= 11.5.0 < 11.5.2 | 11.5.2 |
| mattermost | mattermost | 10.11.0 – 10.11.13 | — |
| mattermost | mattermost | 11.5.0 – 11.5.1 | — |
| mattermost | mattermost_server | >= 10.11.0 < 10.11.14 | 10.11.14 |
| mattermost | mattermost_server | >= 11.5.0 < 11.5.2 | 11.5.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mattermost up to 10.11.13/11.5.1 Slash Command server-side request forgery (EUVD-2026-30755)
vuldb·2026-05-18·CVSS 3.5
CVE-2026-6333 [LOW] Mattermost up to 10.11.13/11.5.1 Slash Command server-side request forgery (EUVD-2026-30755)
A vulnerability identified as critical has been detected in Mattermost up to 10.11.13/11.5.1. Impacted is an unknown function of the component Slash Command Handler. The manipulation leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2026-6333. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
GHSA
GHSA-vqp5-2mrp-qqxg: Mattermost versions 11
ghsa_unreviewed·2026-05-18
CVE-2026-6333 [LOW] CWE-918 GHSA-vqp5-2mrp-qqxg: Mattermost versions 11
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response URLs for custom slash commands which allows an authenticated attacker to redirect slash command responses to an attacker-controlled server via a spoofed Host header.. Mattermost Advisory ID: MMSA-2026-00582
GHSA
Mattermost doesn't validate the Host header when constructing response URLs for custom slash command
ghsa·2026-05-18
CVE-2026-6333 [LOW] CWE-918 Mattermost doesn't validate the Host header when constructing response URLs for custom slash command
Mattermost doesn't validate the Host header when constructing response URLs for custom slash command
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response URLs for custom slash commands which allows an authenticated attacker to redirect slash command responses to an attacker-controlled server via a spoofed Host header.. Mattermost Advisory ID: MMSA-2026-00582
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-18
Published