—
GO-2026-5734
Mattermost MS Teams plugin doesn't limit the request body size on the /lifecycle webhook endpoint in github.com/mattermost/mattermost-plugin-msteams
Details
Mattermost MS Teams plugin doesn't limit the request body size on the /lifecycle webhook endpoint in github.com/mattermost/mattermost-plugin-msteams
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / github.com/mattermost/mattermost-plugin-msteams
Introduced in:
0 Fixed in: 1.15.1-0.20260213190728-6fe4d295592e Fix
go get github.com/mattermost/mattermost-plugin-msteams@v1.15.1-0.20260213190728-6fe4d295592e References
- https://github.com/advisories/GHSA-x274-8qfc-hrgf [ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-21388 [ADVISORY]
- https://github.com/mattermost/mattermost-plugin-msteams/commit/6fe4d295592ecc8767d67e69286cbeec01be3210 [FIX]
- https://github.com/mattermost/mattermost-plugin-msteams/releases/tag/v2.3.2 [WEB]
- https://mattermost.com/security-updates [WEB]