Back

MEDIUM

A crafted SVG attachment can crash a Mattermost server

Published Jun 2, 2022

Description

Uncontrolled resource consumption in Mattermost version 6.6.0 and earlier allows an authenticated attacker to crash the server via a crafted SVG attachment on a post.

Affected products

Remediation

Vendor solution

Configure the maximum file size for message attachments to 20 megabytes or less: https://docs.mattermost.com/configure/configuration-settings.html#maximum-file-size

Metrics

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mattermost
Published Jun 2, 2022
Updated Dec 6, 2024
Reserved Jun 2, 2022
CISA Vulnrichment
Updated Dec 6, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-GWPF-95JC-63RV