CVE-2023-40703: Mattermost

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Mattermost fails to properly limit the characters allowed in different fields of a block in Mattermost Boards allowing a attacker to consume excessive resources, possibly leading to Denial of Service, by patching the field of a block using a specially crafted string. 

Affected products

  • Mattermost Mattermost: up to and including 7.8.12; from 8.0.0, up to and including 8.1.3; from 9.0.0, up to and including 9.0.1; version 9.1.0 only

Published 2023-11-27. Last modified 2026-06-17.