CVE-2018-21259: Mattermost Server
Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.
An issue was discovered in Mattermost Server before 4.10.1, 4.9.4, and 4.8.2. It allows attackers to cause a denial of service (application hang) via a malformed link in a channel.
Affected products
- Mattermost Mattermost Server: before 4.8.2 (fixed in 4.8.2); from 4.9.0, before 4.9.4 (fixed in 4.9.4); from 4.10.0, before 4.10.1 (fixed in 4.10.1)
Published 2020-06-19. Last modified 2026-06-17.