CVE-2024-28053: Mattermost Server

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an attacker to send a very large email payload and crash the server.

Affected products

  • Mattermost Mattermost Server: from 8.1.0, before 8.1.10 (fixed in 8.1.10)

Published 2024-03-15. Last modified 2026-06-17.