CVE Vulnerabilities

CVE-2026-6340

Memory Allocation with Excessive Size Value

Published: May 18, 2026 | Modified: May 19, 2026
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate 7zip archive structure before processing which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted 7zip file with excessive folder declarations.. Mattermost Advisory ID: MMSA-2026-00573

Weakness

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Affected Software

NameVendorStart VersionEnd Version
Mattermost_serverMattermost10.11.0 (including)10.11.14 (excluding)
Mattermost_serverMattermost11.4.0 (including)11.4.4 (excluding)
Mattermost_serverMattermost11.5.0 (including)11.5.2 (excluding)

Potential Mitigations

References