CVE-2026-4054: SVG content served through Mattermost image proxy despite Content-Type restrictions causes client-side denial of service
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to validate the response body of proxied images, which allows a remote attacker to enact client-side DoS via an SVG file served from an attacker-controlled origin under a non-SVG Content-Type header (e.g. image/png) embedded in an og:image meta tag or Markdown image link.. Mattermost Advisory ID: MMSA-2026-00630
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4054?
The severity of CVE-2026-4054 is classified as high because it leads to client-side denial of service.
How do I fix CVE-2026-4054?
To fix CVE-2026-4054, upgrade your Mattermost installation to versions higher than 11.5.1, 10.11.13, or 11.4.3.
Which versions of Mattermost are affected by CVE-2026-4054?
CVE-2026-4054 affects Mattermost versions 11.5.0 to 11.5.1, 10.11.0 to 10.11.13, and 11.4.0 to 11.4.3.
What type of attack is possible due to CVE-2026-4054?
CVE-2026-4054 allows a remote attacker to enact a client-side denial of service by serving unvalidated SVG content.
Is there a workaround for CVE-2026-4054?
There is no official workaround for CVE-2026-4054; the recommended action is to upgrade to a non-vulnerable version.