CVE-2026-20719: Mattermost Server

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to prevent rendering of external SVGs on link embeds which allows unauthenticated users to crash the Mattermost webapp and desktop app via creating an issue or PR on GitHub.. Mattermost Advisory ID: MMSA-2026-00595

Affected products

  • Mattermost Mattermost Server: from 10.11.0, before 10.11.12 (fixed in 10.11.12); from 11.2.0, before 11.2.4 (fixed in 11.2.4); from 11.3.0, before 11.3.2 (fixed in 11.3.2); from 11.4.0, before 11.4.1 (fixed in 11.4.1)

Published 2026-03-25. Last modified 2026-06-17.