Loading HuntDB...

GHSA-qqc8-rv37-79q5

GitHub Security Advisory

Mattermost Server Resource Exhaustion

✓ GitHub Reviewed LOW Has CVE

Advisory Details

Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an attacker to send a very large email payload and crash the server.

Affected Packages

Go github.com/mattermost/mattermost/server/v8
Affected versions: 0 (fixed in 0.0.0-20240209181221-674f549daf0e)
Go github.com/mattermost/mattermost-server
Affected versions: 0 (fixed in 0.0.0-20240209181221-674f549daf0e)
Go github.com/mattermost/mattermost-server/v5
Affected versions: 0 (fixed in 0.0.0-20240209181221-674f549daf0e)
Go github.com/mattermost/mattermost-server/v6
Affected versions: 0 (fixed in 0.0.0-20240209181221-674f549daf0e)

Related CVEs

Key Information

GHSA ID
GHSA-qqc8-rv37-79q5
Published
March 15, 2024 9:30 AM
Last Modified
December 18, 2024 7:21 PM
CVSS Score
2.5 /10
Primary Ecosystem
Go
Primary Package
github.com/mattermost/mattermost/server/v8
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 2, 2025 6:46 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.