GHSA-32h7-7j94-8fc2
GitHub Security Advisory
Mattermost vulnerable to denial of service via large number of emoji reactions
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed to be added in a post, allowing an attacker sending a huge amount of non-existent custom emojis in a post to crash the mobile app of a user seeing the post. Fetching posts with huge amounts of reactions results in Uncontrolled Resource Consumption.
Affected Packages
Go
github.com/mattermost/mattermost/server/v8
Affected versions:
0
(fixed in 8.1.8)
Go
github.com/mattermost/mattermost/server/v8
Affected versions:
9.2.0
(fixed in 9.2.4)
Go
github.com/mattermost/mattermost/server/v8
Affected versions:
9.1.0
(fixed in 9.1.5)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: June 18, 2025 6:25 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.