6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Description
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate decompressed archive entry sizes during file extraction which allows authenticated users with file upload permissions to cause a denial of service via crafted zip archives containing highly compressed entries (zip bombs) that exhaust server memory.. Mattermost Advisory ID: MMSA-2026-00598
Basic Information
ID
CVE-2026-3114
Source
Mattermost
Published
Mar 26, 2026 at 16:21
Modified
Mar 26, 2026 at 17:51
Affected Product
Vendor
Mattermost
Product
Mattermost
Version
11.4.0
Affected Versions
Mattermost Mattermost 11.4.0
Mattermost Mattermost 11.3.0
Mattermost Mattermost 11.2.0
Mattermost Mattermost 10.11.0
Mattermost Mattermost 11.3.0
Mattermost Mattermost 11.2.0
Mattermost Mattermost 10.11.0