Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-6850— Crafted message attachment causes client-side denial of service via markdown parser regex backtracking in Mattermost

CVSS 6.5 · Medium EPSS 0.24% · P15

Possible ATT&CK Techniques 1AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 7

VendorProductVersion RangeStatus
MattermostMattermost11.7.0≤ 11.7.2affected
11.6.0≤ 11.6.4affected
10.11.0≤ 10.11.19affected
11.8.0unaffected
11.7.3unaffected
11.6.5unaffected
10.11.20unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-6850

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Crafted message attachment causes client-side denial of service via markdown parser regex backtracking in Mattermost
Source: CVE Program / CVE List V5
Vulnerability Description
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause a denial of service for all users in a channel via a post containing a specially crafted payload that triggers catastrophic backtracking in the client-side markdown parser.. Mattermost Advisory ID: MMSA-2026-00658
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1333
Source: CVE Program / CVE List V5
Vulnerability Title
Mattermost 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mattermost是美国Mattermost公司开源的一个开源协作平台。 Mattermost存在资源管理错误漏洞,该漏洞源于未能验证消息附件字段值的长度和内容,使得经过身份认证的攻击者可以通过发布包含特制有效载荷的帖子触发客户端markdown解析器的灾难性回溯,导致频道内所有用户遭受拒绝服务攻击。以下版本受到影响:10.11.19及之前的10.11.x版本、11.6.4及之前的11.6.x版本和11.7.2及之前的11.7.x版本。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
MattermostMattermost 11.7.0 ~ 11.7.2 -

II. Public POCs for CVE-2026-6850

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-6850

登录查看更多情报信息。

Same Patch Batch · Mattermost · 2026-07-13 · 10 CVEs total

CVE-2026-101066.5 MEDIUMUnauthorized users can trigger interactive post actions in private channels via action coo
CVE-2026-95715.9 MEDIUMDeactivated user accounts can continue to obtain valid OAuth access tokens via refresh tok
CVE-2026-95975.4 MEDIUMDeactivated guest accounts can authenticate via magic-link token in Mattermost REST API lo
CVE-2026-100855.4 MEDIUMOrdinary group/direct message member can enable group_constrained and remove all channel p
CVE-2026-97084.9 MEDIUMIncoming webhook user attribution via unvalidated webhook owner
CVE-2026-65414.3 MEDIUMUnscoped updates to other playbooks' metric configuration
CVE-2026-98244.3 MEDIUMRemote cluster metadata enumeration via /share-channel autocomplete
CVE-2026-101034.3 MEDIUMAuthenticated remote cluster can modify or delete posts it does not own in Mattermost Conn
CVE-2026-98203.8 LOWMattermost schemes teams endpoint exposes private team invite IDs

IV. Related Vulnerabilities

V. Comments for CVE-2026-6850

No comments yet


Leave a comment