CVE-2026-5132: Unbounded zlib decompression in Calls SDP WebSocket messages
Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit size of unpacked SDP messages compressed with zlib, which allows attacker to deny service or crash server via sending many SDP messages that unpack to large size.. Mattermost Advisory ID: MMSA-2026-00643
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.10.0 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.9.1 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.8.5 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 11.7.8 - Upgrade
Upgrade
Mattermostto a version that resolves this vulnerability.Fixed in 10.11.23 - Compensating control
If immediate upgrade is not possible, mitigate the DoS/crash risk from Calls SDP WebSocket messages by restricting/limiting access to the Mattermost Calls WebSocket endpoint to trusted clients (e.g., via network controls such as firewall/ACL/WAF) until the update to MMSA-2026-00643 fixed versions is completed.
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attack requires low-privileged access. The attacker must be able to send Calls SDP messages over WebSocket; no user interaction is required.
What is the likely impact of successful exploitation?
An attacker can send many zlib-compressed SDP messages that expand to a large size when unpacked, potentially exhausting resources and causing a denial of service or server crash. The provided severity vector indicates no confidentiality or integrity impact.
Which Mattermost release lines are affected?
Affected releases are Mattermost 11.9.x through 11.9.0, 11.8.x through 11.8.4, 11.7.x through 11.7.7, and 10.11.x through 10.11.22.