VDB
KO
MEDIUM 5.3

GHSA-pg7c-462j-grxv

Mattermost doesn't archive the channel before removing persistent notifications

Details

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to archive the channel before removing persistent notifications which allows authenticated user to crash the server via timing the creation of persistent notification message between the server deleting existing persistent notifications and archiving the channel. Mattermost Advisory ID: MMSA-2026-00637.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/mattermost/mattermost-server
Introduced in: 11.6.0 Fixed in: 11.6.1
Fix go get github.com/mattermost/mattermost-server@v11.6.1
Go / github.com/mattermost/mattermost-server
Introduced in: 11.5.0 Fixed in: 11.5.4
Fix go get github.com/mattermost/mattermost-server@v11.5.4
Go / github.com/mattermost/mattermost-server
Introduced in: 11.4.0 Fixed in: 11.4.5
Fix go get github.com/mattermost/mattermost-server@v11.4.5
Go / github.com/mattermost/mattermost-server
Introduced in: 10.11.0 Fixed in: 10.11.15
Fix go get github.com/mattermost/mattermost-server@v10.11.15

References