PT-2025-34259 · Mattermost · Mattermost

Daw10

·

Published

2025-08-21

·

Updated

2025-08-29

·

CVE-2025-8402

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Mattermost versions 10.8.x through 10.8.3 Mattermost versions 10.5.x through 10.5.8 Mattermost versions 9.11.x through 9.11.17 Mattermost versions 10.10.x through 10.10.0 Mattermost versions 10.9.x through 10.9.3
Description: Mattermost fails to validate import data, potentially allowing a system administrator to crash the server via the bulk import feature.
Recommendations: Mattermost versions 10.8.x through 10.8.3: Update to a version later than 10.8.3. Mattermost versions 10.5.x through 10.5.8: Update to a version later than 10.5.8. Mattermost versions 9.11.x through 9.11.17: Update to a version later than 9.11.17. Mattermost versions 10.10.x through 10.10.0: Update to a version later than 10.10.0. Mattermost versions 10.9.x through 10.9.3: Update to a version later than 10.9.3.

Fix

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2025-8402
GHSA-H469-4FCF-P23H
GO-2025-3911

Affected Products

Mattermost