CVE-2026-5132
Received Received - Intake

Denial of Service in Mattermost via Zlib-compressed SDP Messages

Vulnerability report for CVE-2026-5132, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: Mattermost, Inc.

Description

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit size of unpacked SDP messages compressed with zlib, which allows attacker to deny service or crash server via sending many SDP messages that unpack to large size.. Mattermost Advisory ID: MMSA-2026-00643

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-15
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
mattermost mattermost to 11.9.0 (inc)
mattermost mattermost to 11.8.4 (inc)
mattermost mattermost to 11.7.7 (inc)
mattermost mattermost to 10.11.22 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-409 The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Mattermost versions between 11.7.7 and 11.9.0, as well as 10.11.22 and below, have a flaw where they do not properly limit the size of SDP messages after decompression with zlib. This allows attackers to send specially crafted messages that expand to very large sizes, causing the server to run out of resources or crash.

Detection Guidance

Detecting this vulnerability requires monitoring for unusually large SDP messages or server crashes. Check Mattermost logs for errors related to SDP message processing or zlib decompression failures. Monitor network traffic for excessive SDP message volumes.

Impact Analysis

This vulnerability can lead to denial of service, where the Mattermost server becomes unavailable or crashes due to excessive resource consumption. It may disrupt communication and collaboration for users relying on the platform.

Compliance Impact

The vulnerability causes denial of service or server crashes due to excessive resource consumption from unpacked SDP messages. This could disrupt availability of systems handling sensitive data, potentially violating compliance requirements for GDPR (availability of personal data) and HIPAA (access to health information).

Mitigation Strategies

Upgrade Mattermost to a patched version (11.9.1 or later, 11.8.5 or later, 11.7.8 or later, or 10.11.23 or later). If immediate upgrade is not possible, restrict network access to Mattermost servers and monitor for suspicious SDP message activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-5132. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart