MEDIUM 4.3 Go

Mattermost denial of service through long emoji value

GHSA-6mx3-9qfh-77gj · BIT-mattermost-2024-24988 · CVE-2024-24988 · GO-2024-2589

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string as an emoji value causing high resource consumption and possibly crashing the server.

Ready to move

Start Securing

Free, no credit card | First findings in minutes