CVE-2025-14822: DoS from quadratic complexity in model.ParseHashtags
Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources via a single HTTP request containing a post with thousands space-separated tokens
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14822?
CVE-2025-14822 is a high severity vulnerability due to its potential for Denial of Service (DoS) attacks.
How do I fix CVE-2025-14822?
To mitigate CVE-2025-14822, upgrade Mattermost to version 10.11.9 or later where the vulnerability is patched.
Who is affected by CVE-2025-14822?
CVE-2025-14822 affects Mattermost versions 10.11.x up to and including 10.11.8.
What type of attack does CVE-2025-14822 allow?
CVE-2025-14822 allows authenticated attackers to exhaust server CPU resources by sending specially crafted HTTP requests.
What is the impact of CVE-2025-14822?
The impact of CVE-2025-14822 is a potential Denial of Service, leading to degraded performance or unavailability of the Mattermost service.