Security Advisory

CVE-2026-10819

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-27 14:15:25
Last updated 2026-07-27 15:05:28
Assigner Mattermost
CVSS score not scored
State PUBLISHED

Description

Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji.. Mattermost Advisory ID: MMSA-2026-00695