github.com/mattermost/mattermost-server
Go259 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/mattermost/mattermost-serverpage 6 of 6
- CVE-2026-5755MEDIUMCVSS 6.5EG 6.5✓ Fixed in 11.6.1+incompatible2026-05-26
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the TIFF IFD offset in the image header before allocating memory, which allows authenticated users with file u…
- CVE-2026-6333LOWCVSS 3.5EG 3.5✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response URLs for custom slash commands which allows an authenticated attacker to redirect slash command responses to an attacker-…
- CVE-2026-6334LOWCVSS 3.1EG 3.1✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce client identity binding during the OAuth authorization code redemption flow which allows an authenticated OAuth client to redeem authorization codes issued to a diff…
- CVE-2026-6339MEDIUMCVSS 4.3EG 4.3✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1, 11.4.x <= 11.4.3 fail to validate the X-Requested-With header on the burn-on-read reveal endpoint which allows an authenticated channel member to force the reveal of a burn-on-read message without reci…
- CVE-2026-6340MEDIUMCVSS 4.3EG 4.3✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate 7zip archive structure before processing which allows an authenticated attacker to cause server memory exhaustion and denial of service via upload…
- CVE-2026-6343MEDIUMCVSS 4.3EG 4.3✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check public/private permissions which allows members without these permissions to access public playbooks via /get.. Mattermost Advisory ID: MMSA-2026-005…
- CVE-2026-6345MEDIUMCVSS 6.5EG 6.5✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure of created user password which allows a malicious attacker to impersonate a user via the use of some of those passwords.. Mattermost Adviso…
- CVE-2026-6346HIGHCVSS 8.7EG 8.7✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields before including them in support packet generation, which allows a Mattermost System Admin or any party with access…
- CVE-2026-6347HIGHCVSS 7.6EG 7.6✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields in the Mattermost Calls plugin which allows an attacker with access to a support packet to obtain TURN server crede…
Check whether github.com/mattermost/mattermost-server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/mattermost/mattermost-server CVEs against the assets you own.
Start Free Scan →