CVE-2026-3114: Zip Bomb Denial of Service via Unrestricted Archive Decompression
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate decompressed archive entry sizes during file extraction which allows authenticated users with file upload permissions to cause a denial of service via crafted zip archives containing highly compressed entries (zip bombs) that exhaust server memory.. Mattermost Advisory ID: MMSA-2026-00598
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3114?
CVE-2026-3114 has a severity rating that indicates a high potential risk for denial of service attacks due to unvalidated decompressed archive entry sizes.
How do I fix CVE-2026-3114?
To fix CVE-2026-3114, update Mattermost to version 11.4.1 or later, 11.3.2 or later, 11.2.4 or later, or 10.11.12 or later.
What versions of Mattermost are affected by CVE-2026-3114?
CVE-2026-3114 affects Mattermost versions up to and including 11.4.0, 11.3.1, 11.2.3, and 10.11.11.
Who can exploit CVE-2026-3114?
Authenticated users with file upload permissions can exploit CVE-2026-3114 to launch a denial of service attack.
What type of vulnerability is CVE-2026-3114?
CVE-2026-3114 is a denial of service vulnerability specifically related to unrestricted archive decompression.