CyberRota Analysis
This is a low severity vulnerability with a CVSS score of 3.1. Exploitation may require the attacker to be authenticated.
CVE
CVE-2025-14822
Severity
LOW
CVSS
3.1
EPSS
0.32%
Original NVD Description
Mattermost versions 10.11.x <= 10.11.8 fail to validate input size before processing hashtags which allows an authenticated attacker to exhaust CPU resources via a single HTTP request containing a post with thousands space-separated tokens
Related CVEs
Other vulnerabilities affecting the same vendor(s)