cbcvebase.

Github.Com Mattermost Mattermost-Plugin-Msteams vulnerabilities

4 known vulnerabilities affecting github.com/mattermost_mattermost-plugin-msteams.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2LOW1

Vulnerabilities

Page 1 of 1
CVE-2026-24661P4MEDIUM≥ 0, < 1.15.1-0.20260213190728-6fe4d295592e2026-04-09
CVE-2026-24661 [MEDIUM] CWE-770 Mattermost MS Teams plugin doesn't limit the request body size on the /changes webhook endpoint Mattermost MS Teams plugin doesn't limit the request body size on the /changes webhook endpoint Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-006
ghsa
CVE-2026-21388P4LOW≥ 0, < 1.15.1-0.20260213190728-6fe4d295592e2026-04-09
CVE-2026-21388 [LOW] CWE-770 Mattermost MS Teams plugin doesn't limit the request body size on the /lifecycle webhook endpoint Mattermost MS Teams plugin doesn't limit the request body size on the /lifecycle webhook endpoint Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00
ghsa
CVE-2025-27936P4MEDIUM≥ 0, < 2.1.02025-04-16
CVE-2025-27936 [MEDIUM] CWE-208 Mattermost vulnerable to Observable Timing Discrepancy Mattermost vulnerable to Observable Timing Discrepancy Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin via a timing attack during webhook secret comparison.
ghsaosv
CVE-2026-2476P4HIGH≥ 0, < 1.15.1-0.20260102165339-036c761bd3cb2026-03-16
CVE-2026-2476 [HIGH] CWE-200 Mattermost Microsoft Teams Plugin fails to properly mask sensitive configuration values Mattermost Microsoft Teams Plugin fails to properly mask sensitive configuration values Mattermost Plugins versions <=2.0.3.0 fail to properly mask sensitive configuration values which allows an attacker with access to support packets to obtain original plugin settings via exported configuration data. Mattermost Advisory ID: MMSA-2026-00606
ghsaosv
Github.Com Mattermost Mattermost-Plugin-Msteams vulnerabilities | cvebase