CVE-2026-10600

Source
https://cve.org/CVERecord?id=CVE-2026-10600
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10600.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-10600
Downstream
Published
2026-07-27T14:13:29.962Z
Modified
2026-08-05T03:47:28.380366122Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Denial of service via unbounded document content extraction in Mattermost Server
Details

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and resource consumption of server-side document content extraction which allows an authenticated user with file-upload permission to degrade file uploads for all users on the server via repeatedly uploading small documents that are cheap to upload but expensive to extract, saturating the shared extraction worker pool.. Mattermost Advisory ID: MMSA-2026-00694

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "11.8.0"
                },
                {
                    "last_affected": "11.8.0"
                },
                {
                    "introduced": "11.7.0"
                },
                {
                    "last_affected": "11.7.3"
                },
                {
                    "introduced": "11.6.0"
                },
                {
                    "last_affected": "11.6.5"
                },
                {
                    "introduced": "10.11.0"
                },
                {
                    "last_affected": "10.11.20"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10600.json",
    "cna_assigner": "Mattermost",
    "cwe_ids": [
        "CWE-770"
    ]
}
References

Affected packages

Git / github.com/mattermost/mattermost

Affected ranges

Type
GIT
Repo
https://github.com/mattermost/mattermost
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "10.11.0"
        },
        {
            "fixed": "10.11.21"
        },
        {
            "introduced": "11.6.0"
        },
        {
            "fixed": "11.6.6"
        },
        {
            "introduced": "11.7.0"
        },
        {
            "fixed": "11.7.4"
        },
        {
            "introduced": "11.8.0"
        },
        {
            "fixed": "11.8.1"
        }
    ],
    "cpe": "cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE"
}

Affected versions

@mattermost/client@10.*
@mattermost/client@10.11.0
@mattermost/client@11.*
@mattermost/client@11.7.0
@mattermost/client@11.8.0
@mattermost/shared@11.*
@mattermost/shared@11.7.0
@mattermost/shared@11.8.0
@mattermost/types@10.*
@mattermost/types@10.11.0
@mattermost/types@11.*
@mattermost/types@11.7.0
@mattermost/types@11.8.0
mattermost-redux@10.*
mattermost-redux@10.11.0
mattermost-redux@11.*
mattermost-redux@11.7.0
mattermost-redux@11.8.0
v10.*
v10.11.0
v10.11.0-rc3
v10.11.1
v10.11.1-rc1
v10.11.10
v10.11.11
v10.11.11-rc1
v10.11.11-rc2
v10.11.12
v10.11.13
v10.11.13-rc1
v10.11.14
v10.11.14-rc1
v10.11.15
v10.11.15-rc1
v10.11.16
v10.11.17
v10.11.18
v10.11.19
v10.11.19-rc1
v10.11.2
v10.11.2-rc1
v10.11.2-rc2
v10.11.20
v10.11.3
v10.11.4
v10.11.4-rc1
v10.11.4-rc2
v10.11.4-rc3
v10.11.5
v10.11.6
v10.11.7
v10.11.8
v10.11.9
v10.11.9-rc1
v11.*
v11.6.0
v11.6.1
v11.6.1-rc1
v11.6.2
v11.6.3
v11.6.4
v11.6.5
v11.7.0
v11.7.1
v11.7.2
v11.7.3
v11.8.0
v11.8.0-rc5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10600.json"