CVE-2025-35965

MEDIUM

Mattermost 9.11.0-9.11.10, 10.4.0-10.4.2, 10.5.0 - Denial of Service via UpdateRunTaskActions GraphQL Operation

Title source: llm
STIX 2.1

Description

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation, which allows an attacker to create task items containing an excessive number of actions triggered by specific posts, overloading the server and leading to a denial-of-service (DoS) condition.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0034
EPSS Percentile 56.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-770
Status published
Products (4)
mattermost/mattermost 0 - 8.0.0-20250218121836-2b5275d87136Go
mattermost/mattermost-plugin-playbooks 2.0.0Go
mattermost/mattermost_server 10.5.0
mattermost/mattermost_server 9.11.0 - 9.11.11
Published Apr 24, 2025
Tracked Since Feb 18, 2026