PatchSiren cyber security CVE debrief
CVE-2026-5755 Mattermost CVE debrief
CVE-2026-5755 is a denial of service vulnerability in Mattermost Server versions 10.11.x through 11.6.x. Authenticated users with file upload or posting permissions can cause a server OOM by uploading a crafted TIFF file or posting a URL that serves one. This vulnerability occurs due to insufficient validation of TIFF IFD offsets in image headers before memory allocation. Users of affected versions should apply patches or restrict file upload and posting permissions to trusted users.
- Vendor
- Mattermost
- Product
- Unknown
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-22
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-22
- Advisory updated
- 2026-07-23
Who should care
Users of Mattermost Server versions 10.11.x through 11.6.x should apply patches to prevent denial of service attacks. System administrators and security teams responsible for Mattermost deployments should review and implement recommended mitigations.
Technical summary
The vulnerability occurs because Mattermost fails to validate the TIFF IFD offset in the image header before allocating memory. This allows authenticated users with file upload or posting permissions to cause a denial of service (server OOM) via uploading a crafted TIFF file or posting a URL that serves one. The issue is related to image processing and memory management in Mattermost Server. Affected product deployments exist in environments where Mattermost Server versions 10.11.x through 11.6.x are used. Users with file upload or posting permissions can exploit this vulnerability. Defenders should verify affected systems and apply patches or mitigations as recommended by the vendor.
Defensive priority
Medium
Recommended defensive actions
- Apply patches to Mattermost Server versions 10.11.x through 11.6.x
- Restrict file upload and posting permissions to trusted users
- Monitor server resources for signs of OOM
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-05-22T11:16:23.287Z and last modified on 2026-07-23T16:10:00.137Z. The NVD entry is currently Analyzed. Evidence is limited to public sources and may not reflect the full scope or details of the vulnerability. Defenders should verify affected systems and apply patches or mitigations as recommended by the vendor.
Official resources
-
CVE-2026-5755 CVE record
CVE.org
-
CVE-2026-5755 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-22T11:16:23.287Z and has not been modified since then. The NVD entry is currently Analyzed.