SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-10819

MEDIUM · CVSS 6.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

Certain versions of Mattermost are vulnerable to a denial of service due to inadequate restrictions on animated GIF uploads, allowing authenticated attackers to exploit this by uploading malicious files as custom emojis. This could lead to service disruptions, impacting user experience and system availability. Organizations using affected Mattermost versions should prioritize patching to mitigate potential service interruptions.

CVE
CVE-2026-10819
Severity
MEDIUM
CVSS
6.5
EPSS
0.24%

Original NVD Description

Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji.. Mattermost Advisory ID: MMSA-2026-00695

Related CVEs

Other vulnerabilities affecting the same vendor(s)