We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation, which allows an attacker to create task items containing an excessive number of actions triggered by specific posts, overloading the server and leading to a denial-of-service (DoS) condition.
Reserved 2025-04-22 | Published 2025-04-24 | Updated 2025-04-24 | Assigner MattermostCWE-770: Allocation of Resources Without Limits or Throttling
vultza (vultza)
mattermost.com/security-updates
Support options