MEDIUM 4.3 Go
Mattermost denial of service through long emoji value
GHSA-6mx3-9qfh-77gj · BIT-mattermost-2024-24988 · CVE-2024-24988 · GO-2024-2589
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string as an emoji value causing high resource consumption and possibly crashing the server.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes