CVE-2026-20719: DoS via URL Previews Rendering Malicious SVGs
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to prevent rendering of external SVGs on link embeds which allows unauthenticated users to crash the Mattermost webapp and desktop app via creating an issue or PR on GitHub.. Mattermost Advisory ID: MMSA-2026-00595
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20719?
CVE-2026-20719 has a high severity as it allows unauthenticated users to crash the Mattermost web and desktop applications.
How do I fix CVE-2026-20719?
To fix CVE-2026-20719, upgrade to Mattermost version 10.11.12, 11.2.4, 11.3.2, or later.
What versions of Mattermost are affected by CVE-2026-20719?
CVE-2026-20719 affects Mattermost versions 11.4.0 and earlier, 11.3.1 and earlier, 11.2.3 and earlier, and 10.11.11 and earlier.
How does CVE-2026-20719 exploit Mattermost?
CVE-2026-20719 exploits Mattermost by allowing external SVGs to render in link embeds, leading to a denial of service.
Can authenticated users be affected by CVE-2026-20719?
No, CVE-2026-20719 specifically allows unauthenticated users to exploit the vulnerability in Mattermost.