
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2456 is a denial-of-service vulnerability in Mattermost Server caused by the failure to limit the size of responses from integration action endpoints. An authenticated attacker can exploit this to cause server memory exhaustion by configuring a malicious integration server that returns an arbitrarily large response when a user clicks an interactive message button. Affected versions include Mattermost Server 10.11.x ≤ 10.11.10, 11.2.x ≤ 11.2.2, and 11.3.x ≤ 11.3.0. The vulnerability was published on March 16, 2026, and is tracked under Mattermost Advisory ID MMSA-2026-00571. It carries a CVSS v3.1 base score of 5.7 (Medium) (Mattermost Security, ENISA EUVD).
The root cause is classified as CWE-789 (Memory Allocation with Excessive Size Value): Mattermost does not enforce any upper bound on the size of HTTP responses received from third-party integration action endpoints. When a user clicks an interactive message button, the Mattermost server makes a request to the configured integration action URL and reads the response without restriction. A malicious integration server can return an arbitrarily large payload, causing the server to allocate excessive memory while processing it. Exploitation requires the attacker to control or compromise an integration endpoint registered within the Mattermost instance and to induce a legitimate user to click the associated interactive button (Mattermost Security, ENISA EUVD).
Successful exploitation results in server memory exhaustion, rendering the Mattermost server unavailable to legitimate users (high availability impact). There is no confidentiality or integrity impact — the vulnerability is limited to a denial-of-service condition. Because Mattermost is a team collaboration platform, an outage could disrupt internal communications and workflows across all users of the affected instance (Mattermost Security, ENISA EUVD).
mattermost) leading to OOM kills or service restarts; system-level OOM killer events logged in /var/log/syslog or dmesg referencing the Mattermost process.Mattermost has released patched versions addressing this vulnerability: upgrade to 10.11.11 or later (for 10.11.x users), 11.2.3 or later (for 11.2.x users), or 11.3.1 or later (for 11.3.x users). As a workaround, administrators should audit all configured integration endpoints to ensure they point to trusted, internally controlled servers, and consider restricting integration creation/modification permissions to trusted users only. Patches are available via the official Mattermost security updates page (Mattermost Security).
The vulnerability received routine coverage from automated CVE tracking services and security feeds shortly after publication on March 16, 2026, including mentions on CVEFeed, VulDB, and Bluesky CVE notification accounts. An openSUSE security announcement was also issued in relation to this CVE. No notable independent researcher commentary or significant media coverage has been identified beyond standard vulnerability disclosure channels (openSUSE Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."