CVE-2026-24458: DoS attack via login attempts with multi-megabyte passwords
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly handle very long passwords, which allows an attacker to overload the server CPU and memory via executing login attempts with multi-megabyte passwords. Mattermost Advisory ID: MMSA-2026-00587
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24458?
CVE-2026-24458 has been classified as a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2026-24458?
To mitigate CVE-2026-24458, update Mattermost to the latest version that addresses this vulnerability.
What versions of Mattermost are affected by CVE-2026-24458?
CVE-2026-24458 affects Mattermost versions 11.3.x up to 11.3.0, 11.2.x up to 11.2.2, and 10.11.x up to 10.11.10.
What does CVE-2026-24458 exploit?
CVE-2026-24458 exploits the server's inability to handle multi-megabyte password login attempts, leading to resource exhaustion.
What can happen if CVE-2026-24458 is exploited?
If CVE-2026-24458 is exploited, it can lead to server overload, resulting in denial of service and disruption of normal operations.