CVE-2024-2446: Mattermost Server
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Mattermost versions 8.1.x before 8.1.10, 9.2.x before 9.2.6, 9.3.x before 9.3.2, and 9.4.x before 9.4.3 fail to limit the number of @-mentions processed per message, allowing an authenticated attacker to crash the client applications of other users via large, crafted messages.
Affected products
- Mattermost Mattermost Server: from 8.1.0, before 8.1.10 (fixed in 8.1.10); from 9.2.0, before 9.2.6 (fixed in 9.2.6); from 9.3.0, before 9.3.2 (fixed in 9.3.2); from 9.4.0, before 9.4.3 (fixed in 9.4.3)
Published 2024-03-15. Last modified 2026-06-17.