CVE Vulnerabilities

CVE-2026-10819

Improper Handling of Highly Compressed Data (Data Amplification)

Published: Jul 27, 2026 | Modified: Aug 03, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji.. Mattermost Advisory ID: MMSA-2026-00695

Weakness

The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

Affected Software

NameVendorStart VersionEnd Version
Mattermost_serverMattermost10.11.0 (including)10.11.21 (excluding)
Mattermost_serverMattermost11.6.0 (including)11.6.6 (excluding)
Mattermost_serverMattermost11.7.0 (including)11.7.5 (excluding)
Mattermost_serverMattermost11.8.0 (including)11.8.2 (excluding)

References