SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-5132

MEDIUM · CVSS 6.5

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Mattermost versions 11.9.0 and earlier, 11.8.4 and earlier, 11.7.7 and earlier, and 10.11.22 and earlier are vulnerable due to insufficient limitations on the size of unpacked SDP messages compressed with zlib. An attacker can exploit this vulnerability to send numerous SDP messages that expand to a large size, potentially leading to denial of service or server crashes. Organizations using these Mattermost versions should prioritize patching to mitigate the risk of service disruption.

CVE
CVE-2026-5132
Severity
MEDIUM
CVSS
6.5
EPSS
N/A

Original NVD Description

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit size of unpacked SDP messages compressed with zlib, which allows attacker to deny service or crash server via sending many SDP messages that unpack to large size.. Mattermost Advisory ID: MMSA-2026-00643