PT-2025-32583 · Mattermost · Mattermost Confluence Plugin

Lorenzo Gallegos

·

Published

2025-07-10

·

Updated

2025-08-20

·

CVE-2025-54525

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Mattermost Confluence Plugin versions prior to 1.5.0
Description: The Mattermost Confluence Plugin does not properly handle unexpected request bodies. This allows attackers to crash the plugin by repeatedly sending requests with invalid bodies to the channel subscription creation endpoint.
Recommendations: Update the Mattermost Confluence Plugin to version 1.5.0 or later.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09765
CVE-2025-54525
GHSA-3CG3-3MMR-W8HJ
GO-2025-3872
OPENSUSE-SU-2025:15469-1

Affected Products

Mattermost Confluence Plugin