Launch Week Day 1: Announcing Security Design Review
LOW 3.1 Go

Mattermost has an Observable Timing Discrepancy vulnerability

GHSA-xr3w-rmvj-f6m7 · CVE-2025-54499 · GO-2025-4036

Published · Modified

Description

Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to use constant-time comparison for sensitive string comparisons which allows attackers to exploit timing oracles to perform byte-by-byte brute force attacks via response time analysis on Cloud API keys and OAuth client secrets.

Ready to move

Start Securing

Free, no credit card | First findings in minutes