GHSA-mx8m-v8qm-xwr8

Suggest an improvement
Source
https://github.com/advisories/GHSA-mx8m-v8qm-xwr8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-mx8m-v8qm-xwr8/GHSA-mx8m-v8qm-xwr8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mx8m-v8qm-xwr8
Aliases
Published
2026-01-16T12:30:25Z
Modified
2026-02-03T03:11:44.916504Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H CVSS Calculator
Summary
Mattermost is vulnerable to DoS due to infinite re-renders on API errors
Details

Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API errors which allows authenticated users to cause application-level DoS via triggering unbounded component re-render loops.

Database specific
{
    "github_reviewed_at": "2026-01-16T20:58:33Z",
    "severity": "MODERATE",
    "cwe_ids": [
        "CWE-770"
    ],
    "github_reviewed": true,
    "nvd_published_at": "2026-01-16T12:15:49Z"
}
References

Affected packages

Go
github.com/mattermost/mattermost-server

Package

Name
github.com/mattermost/mattermost-server
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost-server

Affected ranges

Type
SEMVER
Events
Introduced
10.11.0
Fixed
10.11.9

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-mx8m-v8qm-xwr8/GHSA-mx8m-v8qm-xwr8.json"
last_known_affected_version_range
"<= 10.11.8"
github.com/mattermost/mattermost-server

Package

Name
github.com/mattermost/mattermost-server
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost-server

Affected ranges

Type
SEMVER
Events
Introduced
11.1.0
Fixed
11.1.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-mx8m-v8qm-xwr8/GHSA-mx8m-v8qm-xwr8.json"
last_known_affected_version_range
"<= 11.1.1"
github.com/mattermost/mattermost-server

Package

Name
github.com/mattermost/mattermost-server
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost-server

Affected ranges

Type
SEMVER
Events
Introduced
11.0.0
Fixed
11.0.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-mx8m-v8qm-xwr8/GHSA-mx8m-v8qm-xwr8.json"
last_known_affected_version_range
"<= 11.0.6"