Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources via a single HTTP request containing a post with thousands space-separated tokens
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-9r42-rhw3-2222 Mattermost is vulnerable to CPU exhaustion via crafted HTTP request
Fixes

Solution

Update Mattermost to versions 11.2.0, 10.11.9 or higher.


Workaround

No workaround given by the vendor.

References
History

Wed, 21 Jan 2026 00:15:00 +0900

Type Values Removed Values Added
First Time appeared Mattermost mattermost Server
Weaknesses CWE-770
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost mattermost Server

Fri, 16 Jan 2026 23:15:00 +0900

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Fri, 16 Jan 2026 22:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 18:00:00 +0900

Type Values Removed Values Added
Description Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources via a single HTTP request containing a post with thousands space-separated tokens
Title DoS from quadratic complexity in model.ParseHashtags
Weaknesses CWE-407
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-01-16T13:00:45.911Z

Reserved: 2025-12-17T11:54:59.643Z

Link: CVE-2025-14822

cve-icon Vulnrichment

Updated: 2026-01-16T13:00:38.106Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-16T09:16:01.460

Modified: 2026-01-20T15:11:19.127

Link: CVE-2025-14822

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-16T22:41:42Z

Weaknesses