CVE Vulnerabilities

CVE-2025-54499

Observable Timing Discrepancy

Published: Oct 16, 2025 | Modified: Oct 21, 2025
CVSS 3.x
3.7
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comparisons which allows attackers to exploit timing oracles to perform byte-by-byte brute force attacks via response time analysis on Cloud API keys and OAuth client secrets

Weakness

Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Affected Software

Name Vendor Start Version End Version
Mattermost_server Mattermost 10.5.0 (including) 10.5.11 (excluding)
Mattermost_server Mattermost 10.11.0 (including) 10.11.3 (excluding)

References