CVE-2025-35965: DoS in Mattermost Playbooks via Excessive Task Actions
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation, which allows an attacker to create task items containing an excessive number of actions triggered by specific posts, overloading the server and leading to a denial-of-service (DoS) condition.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-35965?
CVE-2025-35965 has a medium severity rating due to its potential to allow attackers to create task items with excessive actions.
How do I fix CVE-2025-35965?
To resolve CVE-2025-35965, upgrade Mattermost to versions 10.4.3, 10.5.1, or newer than 9.11.10.
Which versions of Mattermost are affected by CVE-2025-35965?
CVE-2025-35965 affects Mattermost versions 10.4.x up to 10.4.2, 10.5.x up to 10.5.0, and 9.11.x up to 9.11.10.
What kind of attack can be executed through CVE-2025-35965?
CVE-2025-35965 allows an attacker to create task items that can trigger an excessive number of actions, potentially leading to denial of service.
Is there a workaround for CVE-2025-35965 if I cannot upgrade?
Currently, there are no known workarounds for CVE-2025-35965, and upgrading is strongly recommended.