icon

We found results for “

CVE-2025-14822

Good to know:

icon
icon

Date: January 16, 2026

Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources via a single HTTP request containing a post with thousands space-separated tokens

Severity Score

Severity Score

Weakness Type (CWE)

Inefficient Algorithmic Complexity

CWE-407

Allocation of Resources Without Limits or Throttling

CWE-770

Top Fix

icon

Upgrade Version

Upgrade to version github.com/mattermost/mattermost-server - v10.11.9;github.com/mattermost/mattermost-server - v11.2.0;https://github.com/mattermost/mattermost.git - v11.2.0-rc3;https://github.com/mattermost/mattermost.git - v10.11.9

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): LOW

Do you need more information?

Contact Us