CVE-2024-24988: Mattermost Server
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string as an emoji value causing high resource consumption and possibly crashing the server.
Affected products
- Mattermost Mattermost Server: before 8.1.8 (fixed in 8.1.8); from 9.0.0, before 9.1.5 (fixed in 9.1.5); from 9.2.0, before 9.2.4 (fixed in 9.2.4)
Published 2024-02-29. Last modified 2026-06-17.