CVE-2026-15814
Received Received - Intake

Memory Exhaustion in Mattermost Image Uploads

Vulnerability report for CVE-2026-15814, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: Mattermost, Inc.

Description

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit the amount of memory allocated when decoding uploaded image files which allows an authenticated user to cause excessive server memory consumption and potential denial of service via uploading a specially crafted image as a profile picture, channel file attachment, team icon, or custom brand image. Mattermost Advisory ID: MMSA-2026-00719

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-15
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
mattermost mattermost to 11.9.0 (inc)
mattermost mattermost to 11.8.4 (inc)
mattermost mattermost to 11.7.7 (inc)
mattermost mattermost to 10.11.22 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-409 The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Mattermost versions 11.9.0 and earlier, 11.8.4 and earlier, 11.7.7 and earlier, and 10.11.22 and earlier. It involves improper memory allocation when decoding uploaded image files, allowing an authenticated user to consume excessive server memory and potentially cause a denial of service by uploading a specially crafted image as a profile picture, file attachment, team icon, or custom brand image.

Detection Guidance

This vulnerability involves excessive memory consumption when decoding uploaded images. To detect it, monitor system memory usage during file uploads, particularly for images. Check Mattermost logs for failed uploads or memory errors. Use system commands like 'top', 'htop', or 'free -m' to observe memory spikes during uploads. Ensure your Mattermost version is updated beyond the affected range (11.9.0, 11.8.4, 11.7.7, 10.11.22).

Impact Analysis

An attacker with authenticated access could exploit this to overload the server with memory consumption, leading to degraded performance or complete service disruption. This could affect all users by making the Mattermost platform unresponsive or unavailable.

Compliance Impact

The vulnerability allows excessive server memory consumption leading to denial of service, which could disrupt availability of systems handling sensitive data. This may impact compliance with GDPR (availability requirements under Article 32) and HIPAA (Access Control and Availability rules) if systems storing personal or health data are affected.

Mitigation Strategies

Upgrade Mattermost to a version higher than 11.9.0, 11.8.4, 11.7.7, or 10.11.22 to address the memory allocation issue in image decoding.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15814. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart