GHSA-mx8m-v8qm-xwr8

Suggest an improvement
Source
https://github.com/advisories/GHSA-mx8m-v8qm-xwr8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-mx8m-v8qm-xwr8/GHSA-mx8m-v8qm-xwr8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mx8m-v8qm-xwr8
Published
2026-01-16T12:30:25Z
Modified
2026-01-16T21:10:01.124242Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H CVSS Calculator
Summary
Mattermost is vulnerable to DoS due to infinite re-renders on API errors
Details

Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API errors which allows authenticated users to cause application-level DoS via triggering unbounded component re-render loops.

Database specific
{
    "cwe_ids": [
        "CWE-770"
    ],
    "severity": "MODERATE",
    "nvd_published_at": "2026-01-16T12:15:49Z",
    "github_reviewed": true,
    "github_reviewed_at": "2026-01-16T20:58:33Z"
}
References

Affected packages

Go

github.com/mattermost/mattermost-server

Package

Name
github.com/mattermost/mattermost-server
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost-server

Affected ranges

Type
SEMVER
Events
Introduced
10.11.0
Fixed
10.11.9

Database specific

source

"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-mx8m-v8qm-xwr8/GHSA-mx8m-v8qm-xwr8.json"

last_known_affected_version_range

"<= 10.11.8"

github.com/mattermost/mattermost-server

Package

Name
github.com/mattermost/mattermost-server
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost-server

Affected ranges

Type
SEMVER
Events
Introduced
11.1.0
Fixed
11.1.2

Database specific

source

"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-mx8m-v8qm-xwr8/GHSA-mx8m-v8qm-xwr8.json"

last_known_affected_version_range

"<= 11.1.1"

github.com/mattermost/mattermost-server

Package

Name
github.com/mattermost/mattermost-server
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost-server

Affected ranges

Type
SEMVER
Events
Introduced
11.0.0
Fixed
11.0.7

Database specific

source

"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-mx8m-v8qm-xwr8/GHSA-mx8m-v8qm-xwr8.json"

last_known_affected_version_range

"<= 11.0.6"

github.com/mattermost/mattermost/server/v8

Package

Name
github.com/mattermost/mattermost/server/v8
View open source insights on deps.dev
Purl
pkg:golang/github.com/mattermost/mattermost/server/v8

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.0.0-20251210072417-cc6b77b27132

Database specific

source

"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-mx8m-v8qm-xwr8/GHSA-mx8m-v8qm-xwr8.json"