go

github.com/mattermost/mattermost-server

View on go registry
100 Total advisories
100 Vulnerabilities
0 Malware

Vulnerabilities

HIGH 7.5
Go

CVE-2026-5308

Mattermost doesn't enforce request body size limits on plugin HTTP endpoints

MEDIUM 5.3
Go

CVE-2026-4635

Mattermost doesn't archive the channel before removing persistent notifications

MEDIUM 6.5
Go

CVE-2026-4915

Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing

HIGH 7.1
Go

CVE-2026-3473

Mattermost doesn't validate file ownership and access control

MEDIUM 4.3
Go

CVE-2026-4646

Mattermost doesn't validate user-supplied input in API request handlers

MEDIUM 6.5
Go

CVE-2026-5755

Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memory

HIGH 7.5
Go

CVE-2026-5740

Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation

MEDIUM 4.3
Go

CVE-2026-3636

Mattermost doesn't sanitize team member data when returned via API to users without elevated permissions

MEDIUM 5.4
Go

CVE-2026-28735

Mattermost allows authenticated users to gain access to private repositories

UNKNOWN
Go

CVE-2026-4635

Mattermost doesn't archive the channel before removing persistent notifications in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-28735

Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github

UNKNOWN
Go

CVE-2026-4646

Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github

UNKNOWN
Go

CVE-2026-5308

Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github

UNKNOWN
Go

CVE-2026-4915

Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3473

Mattermost doesn't validate file ownership and access control in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-5740

Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-5755

Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memory in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3636

Mattermost doesn't sanitize team member data when returned via API to users without elevated permissions in github.com/mattermost/mattermost-server

LOW 3.1
Go

CVE-2026-6334

Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow

LOW 3.1
Go

CVE-2026-4053

Mattermost doesn't enforce the PostEditTimeLimit on non-message post fields

MEDIUM 6.5
Go

CVE-2026-3590

Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement

LOW 3.8
Go

CVE-2026-3495

Mattermost doesn't escape some variables that could contain malicious content during error page composition

MEDIUM 4.3
Go

CVE-2026-4054

Mattermost doesn't validate the response body of proxied images

MEDIUM 4.3
Go

CVE-2026-3637

Mattermost doesn't check the create_post channel permission during post edit operations

MEDIUM 6.5
Go

CVE-2026-6345

Mattermost doesn't prevent disclosure of created user password

LOW 2.7
Go

CVE-2026-27769

Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace

LOW 3.7
Go

CVE-2026-4273

Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation

MEDIUM 4.3
Go

CVE-2026-28732

Mattermost doesn't enforce slash command trigger-word uniqueness during command updates

MEDIUM 4.3
Go

CVE-2026-6339

Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint

LOW 3.5
Go

CVE-2026-6333

Mattermost doesn't validate the Host header when constructing response URLs for custom slash command

MEDIUM 4.3
Go

CVE-2026-2325

Mattermost doesn't limit the size of the request body on the start meeting API endpoint

UNKNOWN
Go

CVE-2026-6345

Mattermost doesn't prevent disclosure of created user password in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6339

Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-28732

Mattermost doesn't enforce slash command trigger-word uniqueness during command updates in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6333

Mattermost doesn't validate the Host header when constructing response URLs for custom slash command in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3637

Mattermost doesn't check the create_post channel permission during post edit operations in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-27769

Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3114

Mattermost doesn't validate decompressed archive entry sizes during file extraction in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-27659

Mattermost doesn't properly validate CSRF tokens in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6343

Mattermost doesn't check public/private permissions in github.com/mattermost/mattermost-plugin-playbooks

UNKNOWN
Go

CVE-2026-2325

Mattermost doesn't limit the size of the request body on the start meeting API endpoint in github.com/mattermost/mattermost-plugin-msteams-meetings

UNKNOWN
Go

CVE-2026-28741

Mattermost doesn't validate CSRF tokens on an authentication endpoint in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3495

Mattermost doesn't escape some variables that could contain malicious content during error page composition in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-4054

Mattermost doesn't validate the response body of proxied images in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3115

Mattermost allows authenticated guest users to enumerate user IDs outside their allowed visibility scope in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-4053

Mattermost doesn't enforce the PostEditTimeLimit on non-message post fields in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-4273

Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3590

Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6334

Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-4286

Mattermost doesn't check if {{team_id}} was being changed when updating playbooks in github.com/mattermost/mattermost-plugin-playbooks

MEDIUM 4.3
Go

CVE-2026-28759

Mattermost does not verify remote cluster channel access when processing shared channel membership removals

HIGH 8.0
Go

CVE-2026-4858

Mattermost has a Path Traversal issue

MEDIUM 6.5
Go

CVE-2026-5163

Mattermost doesn't verify channel membership when processing AI-assisted message rewrites

HIGH 7.6
Go

CVE-2026-6347

Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin

MEDIUM 5.7
Go

CVE-2026-27656

Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw

HIGH 8.7
Go

CVE-2026-6346

Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation

MEDIUM 4.3
Go

CVE-2026-6340

Mattermost doesn't validate 7zip archive structure before processing

UNKNOWN
Go

CVE-2026-4274

Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-27656

Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6340

Mattermost doesn't validate 7zip archive structure before processing in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-4858

Mattermost has a Path Traversal issue in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6346

Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-28759

Mattermost does not verify remote cluster channel access when processing shared channel membership removals in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-5163

Mattermost doesn't verify channel membership when processing AI-assisted message rewrites in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-20719

Mattermost: Authenticated DoS through failure to prevent rendering of external SVGs on link embeds in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6347

Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin in github.com/mattermost/mattermost-plugin-calls

MEDIUM 5.0
Go

CVE-2026-3113

Mattermost doesn't set permissions on downloaded bulk export

UNKNOWN
Go

CVE-2026-3113

Mattermost doesn't set permissions on downloaded bulk export in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3112

Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3108

Mattermost allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-4055

Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server

MEDIUM 4.3
Go

CVE-2026-26246

Mattermost fails to bound memory allocation when processing PSD image files

UNKNOWN
Go

CVE-2026-26246

Mattermost fails to bound memory allocation when processing PSD image files in github.com/mattermost/mattermost-server

MEDIUM 4.3
Go

CVE-2026-26233

Mattermost doesn't rate limit login requests, allowing DoS

UNKNOWN
Go

CVE-2026-26233

Mattermost doesn't rate limit login requests, allowing DoS in github.com/mattermost/mattermost-server

LOW 3.8
Go

CVE-2025-14573

Mattermost fails to enforce invite permissions when updating team settings

MEDIUM 5.7
Go

CVE-2025-13821

Mattermost fails to sanitize sensitive data in WebSocket messages

MEDIUM 4.3
Go

CVE-2025-14350

Mattermost fails to properly validate team membership when processing channel mentions

MEDIUM 5.4
Go

CVE-2026-0999

Mattermost fails to properly validate login method restrictions

MEDIUM 4.3
Go

CVE-2026-25783

Mattermost fails to properly validate User-Agent header tokens

MEDIUM 5.3
Go

CVE-2026-2456

Mattermost fails to limit the size of responses from integration action endpoints

UNKNOWN
Go

CVE-2026-25783

Mattermost fails to properly validate User-Agent header tokens in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-2456

Mattermost fails to limit the size of responses from integration action endpoints in github.com/mattermost/mattermost-server

LOW 3.1
Go

CVE-2026-22545

Mattermost fails to validate user's authentication method when processing account auth type switch

MEDIUM 4.3
Go

CVE-2026-25780

Mattermost fails to bound memory allocation when processing DOC files

MEDIUM 4.3
Go

CVE-2026-2457

Mattermost allows attackers to spoof permalink embeds

MEDIUM 4.3
Go

CVE-2026-21386

Mattermost fails to use consistent error responses when handling the /mute command

MEDIUM 4.3
Go

CVE-2026-2463

Mattermost fails to filter invite IDs based on user permissions

MEDIUM 4.3
Go

CVE-2026-2455

Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation

MEDIUM 4.3
Go

CVE-2026-4265

Mattermost fails to validate team-specific upload_file permissions

HIGH 7.5
Go

CVE-2026-24458

Mattermost fails to properly handle very long passwords

MEDIUM 4.3
Go

CVE-2026-2458

Mattermost allows a removed team member to enumerate all public channels within a private team

MEDIUM 4.3
Go

CVE-2026-2578

Mattermost fails to preserve the redacted state of burn-on-read posts during deletion

MEDIUM 4.3
Go

CVE-2026-24692

Mattermost fails to properly enforce read permissions in search API endpoints

UNKNOWN
Go

CVE-2026-22545

Mattermost fails to validate user's authentication method when processing account auth type switch in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-21386

Mattermost fails to use consistent error responses when handling the /mute command in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-4265

Mattermost fails to validate team-specific upload_file permissions in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-2455

Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-2578

Mattermost fails to preserve the redacted state of burn-on-read posts during deletion in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-24458

Mattermost fails to properly handle very long passwords in github.com/mattermost/mattermost-server

Ready to move

Start Securing

Free, no credit card | First findings in minutes