CVE-2025-14435: Application-Level DoS via infinite re-render loop in user profile handling
Mattermost versions 10.11.x <= 10.11.8, 11.1.x <= 11.1.1, 11.0.x <= 11.0.6 fail to prevent infinite re-renders on API errors which allows authenticated users to cause application-level DoS via triggering unbounded component re-render loops.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14435?
CVE-2025-14435 is classified as an application-level denial of service vulnerability.
How do I fix CVE-2025-14435?
To fix CVE-2025-14435, upgrade Mattermost to version 10.11.9 or later, or 11.1.2 or later, or 11.0.7 or later.
Which versions of Mattermost are affected by CVE-2025-14435?
Mattermost versions up to and including 10.11.8, 11.1.1, and 11.0.6 are affected by CVE-2025-14435.
What exploit is associated with CVE-2025-14435?
CVE-2025-14435 allows authenticated users to trigger an infinite re-render loop, leading to an application-level denial of service.
What are the implications of CVE-2025-14435?
CVE-2025-14435 can cause service disruptions for users by overwhelming the application with infinite re-renders.