
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-8075 is a Denial of Service vulnerability in the Mattermost Desktop App caused by improper null checking when processing image headers in links. Any authenticated channel member can crash other members' Desktop App instances by posting a malicious link containing an embedded image with missing HTTP headers. Affected versions include ≤5.5.13, 6.0.2.x (before 6.0.3), and 6.2.x (before 6.2.1), with version 6.3.0 and later being unaffected. It was published on July 17, 2026, with Mattermost Advisory ID MMSA-2026-00668. The CVSS v3.1 base score is 6.5 (Medium) (GitHub Advisory, Mattermost Security).
The root cause is classified as CWE-754 (Improper Check for Unusual or Exceptional Conditions): the Mattermost Desktop App fails to perform proper null checks when inspecting HTTP response headers associated with embedded images in posted links. When the Desktop App attempts to render a link preview containing an image that is missing one or more expected headers, the missing null check causes a crash (likely a null pointer dereference) in the client application. The attack vector is network-based, requires low privileges (any authenticated channel member), and no user interaction beyond the victim's app being open in the affected channel (GitHub Advisory).
Successful exploitation results in a crash of the Mattermost Desktop App for all channel members who view the malicious message, causing a denial of service to their client application. There is no impact on confidentiality or integrity — only availability is affected. An attacker with access to any shared channel can repeatedly trigger crashes, effectively preventing targeted users from using the Desktop App until they upgrade or the message is removed (GitHub Advisory, Mattermost Security).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.235%, indicating a low probability of exploitation within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable.
Content-Type or Content-Length headers in the image response).Users should upgrade the Mattermost Desktop App to version 6.3.0, 6.2.1, or 5.13.6 (or later), which contain the fix for this vulnerability (Mattermost Security, GitHub Advisory). As a temporary workaround pending upgrade, administrators can implement access controls to restrict which users are permitted to post links in sensitive channels. Disabling automatic image preview loading in Desktop App settings, if available, may also reduce exposure until the patch is applied.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."