CVE-2026-25783: Denial of service via malformed User-Agent header in getBrowserVersion
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to properly validate User-Agent header tokens which allows an authenticated attacker to cause a request panic via a specially crafted User-Agent header. Mattermost Advisory ID: MMSA-2026-00586
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25783?
CVE-2026-25783 is classified as a Denial of Service vulnerability affecting specific versions of Mattermost.
How do I fix CVE-2026-25783?
To fix CVE-2026-25783, upgrade to Mattermost version 11.3.1 or later, 11.2.3 or later, or 10.11.11 or later.
Which versions of Mattermost are affected by CVE-2026-25783?
Mattermost versions 11.3.0, 11.2.2, and 10.11.10 and earlier are affected by CVE-2026-25783.
What causes the issue in CVE-2026-25783?
CVE-2026-25783 is caused by the failure to properly validate User-Agent header tokens in the affected Mattermost versions.
Can untrusted users exploit CVE-2026-25783?
CVE-2026-25783 requires authentication, meaning only authenticated attackers can exploit this vulnerability.