Generated remediation guidance and an executive summary. No account required.
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to handle incorrectly reported array lengths which allows malicious user to cause OOM errors and crash the server via sending corrupted msgpack frames within websocket messages to calls plugin. Mattermost Advisory ID: MMSA-2025-00537
Cite this page
CVE-2026-2454. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-2454
Use CWE-1287, Mattermost vendor hub and Mattermost Server product page to widen CVE-2026-2454 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-3108, CVE-2026-28741 and CVE-2026-3112 for nearby disclosures in the same product family.