CVE-2026-21388: Unbounded Request Body Read in MS Teams Plugin {{/lifecycle}} Webhook Endpoint
Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00610
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21388?
CVE-2026-21388 is classified as a high severity vulnerability due to its potential for causing denial of service.
How do I fix CVE-2026-21388?
To mitigate CVE-2026-21388, update the Mattermost MS Teams Plugin to version 2.3.2 or later to ensure proper request body size limits.
Who is affected by CVE-2026-21388?
CVE-2026-21388 affects users of Mattermost MS Teams Plugin versions 2.3.1 and earlier.
Can CVE-2026-21388 be exploited remotely?
Yes, an authenticated attacker can exploit CVE-2026-21388 remotely by sending oversized requests to the webhook endpoint.
What types of attacks are associated with CVE-2026-21388?
CVE-2026-21388 is associated with denial of service attacks resulting from memory exhaustion.