Launch Week Day 1: Announcing Security Design Review
LOW 3.7 Go

Mattermost MS Teams plugin doesn't limit the request body size on the /lifecycle webhook endpoint

GHSA-x274-8qfc-hrgf · CVE-2026-21388

Published · Modified

Description

Mattermost Plugins versions <=2.3.1 fail to limit the request body size on the {{/lifecycle}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00610.

Ready to move

Start Securing

Free, no credit card | First findings in minutes