CVE-2026-25780: Memory Exhaustion via Malformed DOC File Upload
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to bound memory allocation when processing DOC files which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted DOC file.. Mattermost Advisory ID: MMSA-2026-00581
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25780?
CVE-2026-25780 is classified as a high-severity vulnerability due to its potential to cause memory exhaustion and denial of service.
How do I fix CVE-2026-25780?
To fix CVE-2026-25780, upgrade Mattermost to version 11.3.1 or later, 11.2.3 or later, or 10.11.11 or later.
Who is affected by CVE-2026-25780?
CVE-2026-25780 affects Mattermost installations running versions 11.3.0, 11.2.2, and 10.11.10.
What kind of attack does CVE-2026-25780 allow?
CVE-2026-25780 allows authenticated attackers to exploit malformed DOC file uploads to exhaust server memory.
Is CVE-2026-25780 a remote or local vulnerability?
CVE-2026-25780 is a local vulnerability that requires authenticated access to exploit.