Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation, which allows an attacker to create task items containing an excessive number of actions triggered by specific posts, overloading the server and leading to a denial-of-service (DoS) condition.
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
29 Sep 2025, 21:10
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:mattermost:mattermost_server:10.5.0:-:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* |
|
| First Time |
Mattermost mattermost Server
Mattermost |
|
| References | () https://mattermost.com/security-updates - Vendor Advisory |
29 Apr 2025, 13:52
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
24 Apr 2025, 07:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-04-24 07:15
Updated : 2025-09-29 21:10
NVD link : CVE-2025-35965
Mitre link : CVE-2025-35965
CVE.ORG link : CVE-2025-35965
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
