Skip to main content
Vulnerability Database/CVE-2026-95666

CVE-2026-95666: Mattermost DOS Vulnerability

CVE-2026-95666 is a denial of service vulnerability in Mattermost that allows authenticated users to cause excessive database load through the bulk reactions endpoint. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-95666 Overview

CVE-2026-95666 affects multiple Mattermost releases where the bulk reactions endpoint fails to limit the length of the post ID array in incoming requests. An authenticated user can submit a crafted POST /api/v4/posts/ids/reactions request containing an oversized array of post identifiers. The server processes the entire array without bounds enforcement, generating excessive database load. Mattermost tracks this issue as advisory MMSA-2026-00771 and categorizes it under [CWE-770] Allocation of Resources Without Limits or Throttling.

Critical Impact

Authenticated users can trigger sustained database resource exhaustion, degrading availability for all Mattermost tenants sharing the affected instance.

Affected Products

  • Mattermost 11.7.x through 11.7.10
  • Mattermost 11.8.x through 11.8.5
  • Mattermost 11.9.x through 11.9.1 and 11.10.x through 11.10.1

Discovery Timeline

  • 2026-09-22 - CVE CVE-2026-95666 published to NVD
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-95666

Vulnerability Analysis

The flaw resides in the POST /api/v4/posts/ids/reactions handler, which accepts an array of post IDs and returns reactions associated with each identifier. The handler does not enforce an upper bound on the array length before dispatching database queries. An authenticated user can submit thousands of post IDs in a single request, forcing the backend to perform expensive lookup and join operations against the reactions and posts tables.

Repeated requests amplify contention on shared database resources. Query latency increases across unrelated workloads, degrading responsiveness for channels, threads, and search operations. The condition qualifies as a resource exhaustion vulnerability rather than a data confidentiality issue.

Root Cause

The root cause is missing input validation on the length of the post ID collection parameter. Mattermost expects a bounded array but does not enforce that expectation server-side. This maps directly to [CWE-770], where the application allocates database work proportional to attacker-controlled input without throttling.

Attack Vector

Exploitation requires network access to the Mattermost API and valid user credentials. No elevated privileges, no user interaction, and no server-side configuration changes are required. Any account with permission to view reactions can invoke the endpoint. The vulnerability affects availability only; confidentiality and integrity remain unaffected.

A proof-of-concept request would issue an HTTP POST to /api/v4/posts/ids/reactions with a JSON body containing an oversized array of post identifiers. Refer to the Mattermost Security Updates advisory for vendor-supplied technical details.

Detection Methods for CVE-2026-95666

Indicators of Compromise

  • Unusually large JSON payloads submitted to POST /api/v4/posts/ids/reactions from a single authenticated session
  • Sustained spikes in database CPU utilization or query latency correlated with reactions endpoint traffic
  • Repeated requests to the bulk reactions endpoint from the same user or IP within short time windows

Detection Strategies

  • Instrument the Mattermost application or upstream proxy to log request body sizes for the bulk reactions endpoint and alert on outliers.
  • Correlate application access logs with database slow-query logs to identify authenticated users driving expensive queries.
  • Deploy a web application firewall rule that inspects the JSON array length in requests to /api/v4/posts/ids/reactions and blocks oversized payloads.

Monitoring Recommendations

  • Establish a baseline for normal request rate and payload size against /api/v4/posts/ids/reactions and alert on sustained deviations.
  • Track per-user API call frequency to detect abuse patterns from compromised or malicious accounts.
  • Monitor PostgreSQL or MySQL connection saturation and query queue depth during business hours.

How to Mitigate CVE-2026-95666

Immediate Actions Required

  • Upgrade to a Mattermost release that includes the fix for MMSA-2026-00771, published under Mattermost Security Updates.
  • Enforce reverse-proxy request size limits and rate limits on the /api/v4/posts/ids/reactions endpoint until patched.
  • Review recent access logs for oversized requests to the bulk reactions endpoint and revoke tokens for abusive accounts.

Patch Information

Mattermost has published fixed releases addressing the affected 11.7.x, 11.8.x, 11.9.x, and 11.10.x branches. Administrators should consult the Mattermost Security Updates portal for exact fixed version numbers and upgrade instructions before applying changes in production.

Workarounds

  • Configure an upstream proxy such as NGINX or a WAF to reject requests to /api/v4/posts/ids/reactions exceeding a defined body size.
  • Apply per-user rate limiting on the reactions API to reduce the impact of repeated abuse.
  • Restrict API token issuance and monitor service accounts that interact with the reactions endpoint programmatically.
bash
# NGINX example: cap request body size and rate-limit the reactions endpoint
limit_req_zone $binary_remote_addr zone=reactions:10m rate=10r/m;

location = /api/v4/posts/ids/reactions {
    client_max_body_size 16k;
    limit_req zone=reactions burst=5 nodelay;
    proxy_pass http://mattermost_upstream;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.