CVE-2026-26233
Vulnerability Summary
Timeline
Description
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to rate limit login requests which allows unauthenticated remote attackers to cause denial of service (server crash and restart) via HTTP/2 single packet attack with 100+ parallel login requests.. Mattermost Advisory ID: MMSA-2025-00566
CVSS Metrics
- v3.1•MEDIUM•Score: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- v3.1•MEDIUM•Score: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.10%• Percentile: 28%
Techniques & Countermeasures
- CWE-400•Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
Affected Systems
- github.com/mattermost•mattermost-server
≥ 8.0.0-20260105080200-d27a2195068d, < 8.0.0-20260217110922-b7d4a1f1f59b | ≥ 11.4.0-rc1+incompatible, < 11.4.1+incompatible | ≥ 11.4.0-rc1, < 11.4.1 | ≥ 11.3.0-rc1, < 11.3.2 | ≥ 11.2.0-rc1, < 11.2.4 | ≥ 10.11.0-rc1, < 10.11.12
- mattermost•mattermost
11.4.0 | ≥ 11.3.0, ≤ 11.3.1 | ≥ 11.2.0, ≤ 11.2.3 | ≥ 10.11.0, ≤ 10.11.11
- mattermost•mattermost_server
≥ 10.11.0, < 10.11.12 | ≥ 11.2.0, < 11.2.4 | ≥ 11.3.0, < 11.3.2 | ≥ 11.4.0, < 11.4.1