Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array lengths which allows malicious user to cause OOM errors and crash the server via sending corrupted msgpack frames within websocket messages to calls plugin. Mattermost Advisory ID: MMSA-2025-00537
References
History

Mon, 16 Mar 2026 20:30:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array lengths which allows malicious user to cause OOM errors and crash the server via sending corrupted msgpack frames within websocket messages to calls plugin. Mattermost Advisory ID: MMSA-2025-00537
Title DoS in Calls plugin via malformed msgpack in websocket request.
Weaknesses CWE-1287
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-03-16T20:10:16.644Z

Reserved: 2026-02-13T10:11:47.778Z

Link: CVE-2026-2454

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-16T21:16:33.890

Modified: 2026-03-16T21:16:33.890

Link: CVE-2026-2454

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.