CVE-2026-2456: Denial of Service via Unbounded Memory Allocation in Integration Actions
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 Mattermost fails to limit the size of responses from integration action endpoints, which allows an authenticated attacker to cause server memory exhaustion and denial of service via a malicious integration server that returns an arbitrarily large response when a user clicks an interactive message button. Mattermost Advisory ID: MMSA-2026-00571
Other sources
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 Mattermost fails to limit the size of responses from integration action endpoints, which allows an authenticated attacker to cause server memory exhaustion and denial of service via a malicious integration server that returns an arbitrarily large response when a user clicks an interactive message button.. Mattermost Advisory ID: MMSA-2026-00571
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2456?
CVE-2026-2456 is classified as a Denial of Service vulnerability.
How do I fix CVE-2026-2456?
To mitigate CVE-2026-2456, upgrade to Mattermost versions that are above 11.3.0, 11.2.2, and 10.11.10.
What causes CVE-2026-2456?
CVE-2026-2456 is caused by Mattermost failing to limit the size of responses from integration action endpoints.
Who is affected by CVE-2026-2456?
Authenticated users of Mattermost versions 11.3.x up to 11.3.0, 11.2.x up to 11.2.2, and 10.11.x up to 10.11.10 are affected by CVE-2026-2456.
What are the potential impacts of CVE-2026-2456?
The potential impact of CVE-2026-2456 is server memory exhaustion, leading to service downtime.