CVE-2026-24458
Vulnerability Summary
Timeline
Description
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords, which allows an attacker to overload the server CPU and memory via executing login attempts with multi-megabyte passwords. Mattermost Advisory ID: MMSA-2026-00587
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.06%• Percentile: 20%
Techniques & Countermeasures
- CWE-770•Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Affected Systems
- github.com/mattermost•mattermost-server
≥ 11.3.0-rc1+incompatible, < 11.3.1+incompatible | < 5.3.2-0.20260129164748-7201f42d955f | ≥ 10.11.0-rc1, < 10.11.11 | ≥ 11.2.0-rc1, < 11.2.3 | ≥ 11.3.0-rc1, < 11.3.1
- github.com/mattermost/mattermost-server•v5
all
- github.com/mattermost/mattermost-server•v6
all
- github.com/mattermost/mattermost/server•v8
< 8.0.0-20260129164748-7201f42d955f
- mattermost•mattermost
11.3.0 | ≥ 11.2.0, ≤ 11.2.2 | ≥ 10.11.0, ≤ 10.11.10
- mattermost•mattermost_server
≥ 10.11.0, < 10.11.11 | ≥ 11.2.0, < 11.2.3 | ≥ 11.3.0, < 11.3.1