
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25780 is a memory exhaustion vulnerability in Mattermost Server that allows an authenticated attacker to cause denial of service by uploading a specially crafted DOC file. It affects Mattermost Server versions 11.3.x ≤ 11.3.0, 11.2.x ≤ 11.2.2, and 10.11.x ≤ 10.11.10. The vulnerability was disclosed on March 16, 2026, and is tracked under Mattermost Advisory ID MMSA-2026-00581. It carries a CVSS v3.1 base score of 4.3 (Medium) (Red Hat Bugzilla, Mattermost Security).
The root cause is a failure to bound memory allocation when parsing DOC files, classified as CWE-789 (Memory Allocation with Excessive Size Value) and CWE-770 (Allocation of Resources Without Limits or Throttling). An authenticated attacker can upload a maliciously crafted DOC file via the standard file upload interface; the server's DOC processing logic allocates memory without enforcing upper limits, leading to unbounded heap growth. No user interaction is required beyond the initial file upload, and the attack is conducted over the network with low-privilege credentials (Red Hat Bugzilla, Mattermost Security).
Successful exploitation results in server memory exhaustion, causing a denial of service condition that makes the Mattermost server unavailable to all legitimate users. There is no impact on confidentiality or data integrity — the vulnerability is limited to availability. Because Mattermost is a team collaboration platform, a successful DoS attack could disrupt internal communications and workflows for all users of the affected instance (Red Hat Bugzilla).
.doc file attachments./var/log/syslog, journalctl) coinciding with file upload events.mattermost process RSS/VSZ) following a file upload event; OOM killer invocations targeting the Mattermost process..doc files in the Mattermost file storage directory.Upgrade Mattermost Server to the following patched versions: 11.3.1 or later (for 11.3.x users), 11.2.3 or later (for 11.2.x users), or 10.11.11 or later (for 10.11.x users). As a temporary workaround, administrators can restrict file upload permissions to limit which users can upload files, and implement file size limits and content-type validation at the reverse proxy or application level to reduce exposure. Monitoring server memory consumption for unusual spikes following file upload events is also recommended (Mattermost Security, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."