Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources via a single HTTP request containing a post with thousands space-separated tokens
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-9r42-rhw3-2222 Mattermost is vulnerable to CPU exhaustion via crafted HTTP request
Fixes

Solution

Update Mattermost to versions 11.2.0, 10.11.9 or higher.


Workaround

No workaround given by the vendor.

References
History

Fri, 16 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Fri, 16 Jan 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 09:00:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources via a single HTTP request containing a post with thousands space-separated tokens
Title DoS from quadratic complexity in model.ParseHashtags
Weaknesses CWE-407
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-01-16T13:00:45.911Z

Reserved: 2025-12-17T11:54:59.643Z

Link: CVE-2025-14822

cve-icon Vulnrichment

Updated: 2026-01-16T13:00:38.106Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-16T09:16:01.460

Modified: 2026-01-16T15:55:12.257

Link: CVE-2025-14822

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-16T13:41:42Z

Weaknesses