CVE-2026-6340
published 2026-05-18CVE-2026-6340: Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate 7zip archive structure before processing which allows an…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.24%
15.2th percentile
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate 7zip archive structure before processing which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted 7zip file with excessive folder declarations.. Mattermost Advisory ID: MMSA-2026-00573
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 0 < 5.3.2-0.20260325191733-fb11968f8798 | 5.3.2-0.20260325191733-fb11968f8798 |
| github.com | mattermost_mattermost_server_v8 | >= 0 < 8.0.0-20260325191733-fb11968f8798 | 8.0.0-20260325191733-fb11968f8798 |
| github.com | mattermost_mattermost_server_v8 | >= 10.11.0 < 10.11.14 | 10.11.14 |
| github.com | mattermost_mattermost_server_v8 | >= 11.4.0 < 11.4.4 | 11.4.4 |
| github.com | mattermost_mattermost_server_v8 | >= 11.5.0 < 11.5.2 | 11.5.2 |
| mattermost | mattermost | 10.11.0 – 10.11.13 | — |
| mattermost | mattermost | 11.4.0 – 11.4.3 | — |
| mattermost | mattermost | 11.5.0 – 11.5.1 | — |
| mattermost | mattermost_server | >= 10.11.0 < 10.11.14 | 10.11.14 |
| mattermost | mattermost_server | >= 11.4.0 < 11.4.4 | 11.4.4 |
| mattermost | mattermost_server | >= 11.5.0 < 11.5.2 | 11.5.2 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Mattermost doesn't validate 7zip archive structure before processing
ghsa·2026-05-18
CVE-2026-6340 [MEDIUM] CWE-789 Mattermost doesn't validate 7zip archive structure before processing
Mattermost doesn't validate 7zip archive structure before processing
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate 7zip archive structure before processing which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted 7zip file with excessive folder declarations.. Mattermost Advisory ID: MMSA-2026-00573
GHSA
GHSA-cjm8-jxpw-g43m: Mattermost versions 11
ghsa_unreviewed·2026-05-18
CVE-2026-6340 [MEDIUM] CWE-789 GHSA-cjm8-jxpw-g43m: Mattermost versions 11
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate 7zip archive structure before processing which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted 7zip file with excessive folder declarations.. Mattermost Advisory ID: MMSA-2026-00573
VulDB
Mattermost up to 10.11.13/11.4.3/11.5.1 memory allocation (EUVD-2026-30744)
vuldb·2026-05-18·CVSS 4.3
CVE-2026-6340 [MEDIUM] Mattermost up to 10.11.13/11.4.3/11.5.1 memory allocation (EUVD-2026-30744)
A vulnerability classified as problematic was found in Mattermost up to 10.11.13/11.4.3/11.5.1. The impacted element is an unknown function. Such manipulation leads to uncontrolled memory allocation.
This vulnerability is listed as CVE-2026-6340. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-24683 freerdp: FreeRDP has a heap-use-after-free in ainput_send_input_event
bugzilla·2026-02-09·CVSS 8.7
CVE-2026-24683 [HIGH] CVE-2026-24683 freerdp: FreeRDP has a heap-use-after-free in ainput_send_input_event
CVE-2026-24683 freerdp: FreeRDP has a heap-use-after-free in ainput_send_input_event
FreeRDP is a free implementation of the Remote Desktop Protocol. ainput_send_input_event caches channel_callback in a local variable and later uses it without synchronization; a concurrent channel close can free or reinitialize the callback, leading to a use after free. Prior to 3.22.0, This vulnerability is fixed in 3.22.0.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:6340 https://access.redhat.com/errata/RHSA-2026:6340
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.6 Extended Update Support
Via RHSA-2026:6727 https://access.redhat.com/errata/RHSA-2026:6727
---
This issue has been addressed
Bugzilla
CVE-2026-24491 freerdp: FreeRDP has a heap-use-after-free in video_timer
bugzilla·2026-02-09·CVSS 7.7
CVE-2026-24491 [HIGH] CVE-2026-24491 freerdp: FreeRDP has a heap-use-after-free in video_timer
CVE-2026-24491 freerdp: FreeRDP has a heap-use-after-free in video_timer
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, video_timer can send client notifications after the control channel is closed, dereferencing a freed callback and triggering a use after free. This vulnerability is fixed in 3.22.0.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:6340 https://access.redhat.com/errata/RHSA-2026:6340
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.6 Extended Update Support
Via RHSA-2026:6727 https://access.redhat.com/errata/RHSA-2026:6727
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10.0 Extended Update
Bugzilla
CVE-2026-24676 freerdp: FreeRDP: Denial of Service via use-after-free in AUDIN format renegotiation
bugzilla·2026-02-09·CVSS 7.7
CVE-2026-24676 [HIGH] CVE-2026-24676 freerdp: FreeRDP: Denial of Service via use-after-free in AUDIN format renegotiation
CVE-2026-24676 freerdp: FreeRDP: Denial of Service via use-after-free in AUDIN format renegotiation
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, AUDIN format renegotiation frees the active format list while the capture thread continues using audin->format, leading to a use after free in audio_format_compatible. This vulnerability is fixed in 3.22.0.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:6340 https://access.redhat.com/errata/RHSA-2026:6340
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.6 Extended Update Support
Via RHSA-2026:6727 https://access.redhat.com/errata/RHSA-2026:6727
---
This issue has been addressed in the following produ
Bugzilla
CVE-2026-24675 freerdp: FreeRDP has a Heap-use-after-free in urb_select_interface
bugzilla·2026-02-09·CVSS 7.7
CVE-2026-24675 [HIGH] CVE-2026-24675 freerdp: FreeRDP has a Heap-use-after-free in urb_select_interface
CVE-2026-24675 freerdp: FreeRDP has a Heap-use-after-free in urb_select_interface
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, urb_select_interface can free the device's MS config on error but later code still dereferences it, leading to a use after free in libusb_udev_select_interface. This vulnerability is fixed in 3.22.0.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:6340 https://access.redhat.com/errata/RHSA-2026:6340
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.6 Extended Update Support
Via RHSA-2026:6727 https://access.redhat.com/errata/RHSA-2026:6727
---
This issue has been addressed in the following products:
Red Hat Enterprise
Bugzilla
CVE-2026-23948 freerdp: FreeRDP has a NULL Pointer Dereference in rdp_write_logon_info_v2()
bugzilla·2026-02-09·CVSS 6.9
CVE-2026-23948 [MEDIUM] CVE-2026-23948 freerdp: FreeRDP has a NULL Pointer Dereference in rdp_write_logon_info_v2()
CVE-2026-23948 freerdp: FreeRDP has a NULL Pointer Dereference in rdp_write_logon_info_v2()
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, a NULL pointer dereference vulnerability in rdp_write_logon_info_v2() allows a malicious RDP server to crash FreeRDP proxy by sending a specially crafted LogonInfoV2 PDU with cbDomain=0 or cbUserName=0. This vulnerability is fixed in 3.22.0.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:6340 https://access.redhat.com/errata/RHSA-2026:6340
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.6 Extended Update Support
Via RHSA-2026:6727 https://access.redhat.com/errata/RHSA-2026:6727
---
This issue has been addre
Bugzilla
CVE-2026-24679 freerdp: FreeRDP has a heap-buffer-overflow in urb_select_interface
bugzilla·2026-02-09·CVSS 8.7
CVE-2026-24679 [HIGH] CVE-2026-24679 freerdp: FreeRDP has a heap-buffer-overflow in urb_select_interface
CVE-2026-24679 freerdp: FreeRDP has a heap-buffer-overflow in urb_select_interface
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, The URBDRC client uses server-supplied interface numbers as array indices without bounds checks, causing an out-of-bounds read in libusb_udev_select_interface. This vulnerability is fixed in 3.22.0.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:6340 https://access.redhat.com/errata/RHSA-2026:6340
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.6 Extended Update Support
Via RHSA-2026:6727 https://access.redhat.com/errata/RHSA-2026:6727
---
This issue has been addressed in the following products:
Red Hat Enterprise
Bugzilla
CVE-2026-24684 freerdp: FreeRDP has a Heap-use-after-free in play_thread
bugzilla·2026-02-09·CVSS 8.7
CVE-2026-24684 [HIGH] CVE-2026-24684 freerdp: FreeRDP has a Heap-use-after-free in play_thread
CVE-2026-24684 freerdp: FreeRDP has a Heap-use-after-free in play_thread
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, the RDPSND async playback thread can process queued PDUs after the channel is closed and internal state is freed, leading to a use after free in rdpsnd_treat_wave. This vulnerability is fixed in 3.22.0.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:6340 https://access.redhat.com/errata/RHSA-2026:6340
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.6 Extended Update Support
Via RHSA-2026:6727 https://access.redhat.com/errata/RHSA-2026:6727
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux
Bugzilla
CVE-2026-24681 freerdp: FreeRDP has a heap-use-after-free in urb_bulk_transfer_cb
bugzilla·2026-02-09·CVSS 8.7
CVE-2026-24681 [HIGH] CVE-2026-24681 freerdp: FreeRDP has a heap-use-after-free in urb_bulk_transfer_cb
CVE-2026-24681 freerdp: FreeRDP has a heap-use-after-free in urb_bulk_transfer_cb
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, aAsynchronous bulk transfer completions can use a freed channel callback after URBDRC channel close, leading to a use after free in urb_write_completion. This vulnerability is fixed in 3.22.0.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:6340 https://access.redhat.com/errata/RHSA-2026:6340
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.6 Extended Update Support
Via RHSA-2026:6727 https://access.redhat.com/errata/RHSA-2026:6727
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 1
Bugzilla
CVE-2026-23732 freerdp: FreeRDP: Denial of Service via FastGlyph parsing buffer overflow
bugzilla·2026-01-19·CVSS 5.5
CVE-2026-23732 [MEDIUM] CVE-2026-23732 freerdp: FreeRDP: Denial of Service via FastGlyph parsing buffer overflow
CVE-2026-23732 freerdp: FreeRDP: Denial of Service via FastGlyph parsing buffer overflow
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, FastGlyph parsing trusts `cbData`/remaining length and never validates against the minimum size implied by `cx/cy`. A malicious server can trigger a client‑side global buffer overflow, causing a crash (DoS). Version 3.21.0 contains a patch for the issue.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:6340 https://access.redhat.com/errata/RHSA-2026:6340
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.6 Extended Update Support
Via RHSA-2026:6727 https://access.redhat.com/errata/RHSA-2026:6727
---
This is
Bugzilla
CVE-2026-22854 freerdp: FreeRDP heap-buffer-overflow
bugzilla·2026-01-14·CVSS 6.8
CVE-2026-22854 [MEDIUM] CVE-2026-22854 freerdp: FreeRDP heap-buffer-overflow
CVE-2026-22854 freerdp: FreeRDP heap-buffer-overflow
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap-buffer-overflow occurs in drive read when a server-controlled read length is used to read file data into an IRP output stream buffer without a hard upper bound, allowing an oversized read to overwrite heap memory. This vulnerability is fixed in 3.20.1.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:6340 https://access.redhat.com/errata/RHSA-2026:6340
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.6 Extended Update Support
Via RHSA-2026:6727 https://access.redhat.com/errata/RHSA-2026:6727
---
This issue has been addressed in the following
Bugzilla
CVE-2026-22852 freerdp: FreeRDP heap-buffer-overflow
bugzilla·2026-01-14·CVSS 6.8
CVE-2026-22852 [MEDIUM] CVE-2026-22852 freerdp: FreeRDP heap-buffer-overflow
CVE-2026-22852 freerdp: FreeRDP heap-buffer-overflow
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client when processing Audio Input (AUDIN) format lists. audin_process_formats reuses callback->formats_count across multiple MSG_SNDIN_FORMATS PDUs and writes past the newly allocated formats array, causing memory corruption and a crash. This vulnerability is fixed in 3.20.1.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:6340 https://access.redhat.com/errata/RHSA-2026:6340
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.6 Extended Update Support
Via RHSA-2026:6727 htt
Bugzilla
CVE-2026-22856 freerdp: FreeRDP heap-use-after-free
bugzilla·2026-01-14·CVSS 6.8
CVE-2026-22856 [MEDIUM] CVE-2026-22856 freerdp: FreeRDP heap-use-after-free
CVE-2026-22856 freerdp: FreeRDP heap-use-after-free
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race in the serial channel IRP thread tracking allows a heap use‑after‑free when one thread removes an entry from serial->IrpThreads while another reads it. This vulnerability is fixed in 3.20.1.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:6340 https://access.redhat.com/errata/RHSA-2026:6340
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.6 Extended Update Support
Via RHSA-2026:6727 https://access.redhat.com/errata/RHSA-2026:6727
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10.0 Extended Update Suppo
2026-05-18
Published