Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to update channel subscription endpoint with an invalid request body.
[ { "events": [ { "introduced": "0" }, { "fixed": "1.5.0" } ] } ]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-52931.json"