LOW 3.1 Go
Mattermost has an Observable Timing Discrepancy vulnerability
GHSA-xr3w-rmvj-f6m7 · CVE-2025-54499 · GO-2025-4036
Published · Modified
Description
Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comparisons which allows attackers to exploit timing oracles to perform byte-by-byte brute force attacks via response time analysis on Cloud API keys and OAuth client secrets.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-54499
- WEB https://github.com/mattermost/mattermost/commit/38208b8f065f0786eac0e968f9d754b91b62878c
- WEB https://github.com/mattermost/mattermost/commit/97a4c7839cf5610cfe17c52042878aebb7678372
- PACKAGE https://github.com/mattermost/mattermost
- WEB https://mattermost.com/security-updates
Ready to move
Start Securing
Free, no credit card | First findings in minutes