Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources via a single HTTP request containing a post with thousands space-separated tokens.
{
"cwe_ids": [
"CWE-407",
"CWE-770"
],
"severity": "LOW",
"nvd_published_at": "2026-01-16T09:16:01Z",
"github_reviewed": true,
"github_reviewed_at": "2026-01-16T20:54:02Z"
}