CVE-2026-10600 Details
Description
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all users on the server via repeatedly uploading small documents that are cheap to upload but expensive to extract, saturating the shared extraction worker pool.. Mattermost Advisory ID: MMSA-2026-00694
A denial-of-service vulnerability has been identified in Mattermost versions 11.8.x through 11.8.0, 11.7.x through 11.7.3, 11.6.x through 11.6.5, and 10.11.x through 10.11.20. The issue arises from the application's failure to properly limit the time and resources used during server-side document content extraction. This flaw allows an authenticated user with file-upload privileges to disrupt file uploads for all users on the server. The vulnerability can be exploited by repeatedly uploading small documents that are inexpensive to upload but resource-intensive to process, thereby overwhelming the shared extraction worker pool.
Users can upgrade to Mattermost versions 11.9.0, 11.7.11, or 10.11.22 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://mattermost.com/security-updates | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mattermost mattermost server | >= 10.11.0, < 10.11.21 >= 11.6.0, < 11.6.6 >= 11.7.0, < 11.7.4 >= 11.8.0, < 11.8.1 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 3, 2026 | Initial Analysis | [email protected] |
| Jul 27, 2026 | CVE Modified | CISA-ADP |
| Jul 27, 2026 | New CVE Received | [email protected] |