Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to parse Markdown autolinks with unmatched trailing closing parentheses in linear time, which allows an authenticated user with permission to create posts to cause excessive server CPU consumption and degrade availability for other users via specially crafted post or message attachment content. Mattermost Advisory ID: MMSA-2026-00703

Project Subscriptions

Vendors Products
Mattermost Subscribe
Mattermost Subscribe
Advisories

No advisories yet.

Fixes

Solution

Update Mattermost to versions 11.10.0, 11.9.1, 11.8.5, 11.7.8, 10.11.23 or higher.


Workaround

No workaround given by the vendor.

References
History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to parse Markdown autolinks with unmatched trailing closing parentheses in linear time, which allows an authenticated user with permission to create posts to cause excessive server CPU consumption and degrade availability for other users via specially crafted post or message attachment content. Mattermost Advisory ID: MMSA-2026-00703
Title Mattermost Markdown autolink parsing denial of service
Weaknesses CWE-407
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-09-14T11:19:45.988Z

Reserved: 2026-06-22T10:27:00.877Z

Link: CVE-2026-12882

cve-icon Vulnrichment

Updated: 2026-09-14T11:13:45.501Z

cve-icon NVD

Status : Received

Published: 2026-09-14T11:17:03.050

Modified: 2026-09-14T12:17:38.030

Link: CVE-2026-12882

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-14T12:15:19Z

Weaknesses