CVE-2026-24661: Unbounded Request Body Read in MS Teams Plugin {{/changes}} Webhook Endpoint
Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00611
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24661?
CVE-2026-24661 has a high severity rating due to its potential for causing denial of service through memory exhaustion.
How do I fix CVE-2026-24661?
To fix CVE-2026-24661, update the MS Teams Plugin to version 2.1.3.1 or later to ensure proper request body size limits.
What impacts does CVE-2026-24661 have on Mattermost users?
CVE-2026-24661 can lead to service disruption for Mattermost users by allowing authenticated attackers to exhaust server memory.
Which versions of Mattermost are affected by CVE-2026-24661?
CVE-2026-24661 affects Mattermost MS Teams Plugin versions up to and including 2.1.3.0.
Is authentication required to exploit CVE-2026-24661?
Yes, an authenticated attacker can exploit CVE-2026-24661 by sending oversized requests to the affected webhook endpoint.