CVE-2026-15814: Uploading a crafted image causes excessive memory allocation in the Mattermost Server
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit the amount of memory allocated when decoding uploaded image files which allows an authenticated user to cause excessive server memory consumption and potential denial of service via uploading a specially crafted image as a profile picture, channel file attachment, team icon, or custom brand image. Mattermost Advisory ID: MMSA-2026-00719
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermost Serverto a version that resolves this vulnerability.Fixed in 11.10.0 - Upgrade
Upgrade
Mattermost Serverto a version that resolves this vulnerability.Fixed in 11.9.1 - Upgrade
Upgrade
Mattermost Serverto a version that resolves this vulnerability.Fixed in 11.8.5 - Upgrade
Upgrade
Mattermost Serverto a version that resolves this vulnerability.Fixed in 11.7.8 - Upgrade
Upgrade
Mattermost Serverto a version that resolves this vulnerability.Fixed in 10.11.23
Event History
Frequently Asked Questions
Does exploiting this issue require administrative privileges or user interaction?
An attacker needs an authenticated Mattermost account with the ability to upload an image. No user interaction is required, and the attack can be performed over the network.
Which image-upload functions should be included in exposure assessment?
Assess profile-picture uploads, channel file attachments, team-icon uploads, and custom brand-image uploads. A specially crafted image submitted through any of these paths can trigger excessive server memory consumption.
What is the expected security impact?
The stated impact is excessive memory consumption that can cause a potential denial of service. The supplied vector indicates availability impact, with no stated confidentiality or integrity impact.