
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20719 is a denial-of-service vulnerability in Mattermost Server caused by improper handling of external SVG rendering in link embeds. Affected versions include 10.11.x ≤ 10.11.11, 11.2.x ≤ 11.2.3, 11.3.x ≤ 11.3.1, and 11.4.x ≤ 11.4.0. The flaw allows unauthenticated users to crash the Mattermost webapp and desktop application by embedding malicious external SVG content via a GitHub issue or pull request. It was published on March 25, 2026, and tracked under Mattermost Advisory ID MMSA-2026-00595. The CVSS v3.1 base score is 7.5 (High) (Mattermost Security, Red Hat CVE).
The root cause is classified as CWE-754 (Improper Check for Unusual or Exceptional Conditions) — specifically, Mattermost fails to validate or block the rendering of external SVG files when generating link embed previews. When a Mattermost instance fetches and renders a link preview for a GitHub issue or PR containing a malicious external SVG, the SVG content is processed without adequate sanitization or error handling, causing the client application to crash. The attack vector is network-based, requires no authentication, no privileges, and no user interaction beyond the victim's Mattermost client loading the embed, making it low-complexity to trigger (Mattermost Security, Red Hat CVE).
Successful exploitation results in a denial-of-service condition affecting both the Mattermost web application and desktop client, crashing them for any user who views the affected link embed. The impact is limited to availability — there is no confidentiality or integrity impact. Organizations relying on Mattermost for team communication could experience significant disruption if the crash is triggered repeatedly or at scale, effectively rendering the platform inaccessible to affected users (Mattermost Security).
Mattermost has released patched versions addressing this vulnerability: 10.11.12, 11.2.4, 11.3.2, and 11.4.1 or later. Organizations should upgrade affected deployments to one of these versions as soon as possible. As a temporary workaround until patching is complete, administrators can consider disabling link preview functionality in Mattermost's system console or implementing network-level controls to restrict the Mattermost server from fetching external SVG content from untrusted sources (Mattermost Security).
The vulnerability received standard automated coverage across CVE tracking platforms and security feeds shortly after disclosure on March 25, 2026, including entries on CVEfeed, VulDB, ENISA's EUVD, and a Bluesky post from a CVE tracking account. Red Hat also published a CVE advisory page. No notable independent researcher commentary or significant media coverage has been identified beyond routine vulnerability database entries (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."