CVE-2026-24661 - Unbounded Request Body Read in MS Teams Plugin {{/changes}} Webhook Endpoint
CVE ID :CVE-2026-24661
Published : April 9, 2026, 11:16 a.m. | 1 hour, 52 minutes ago
Description :Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00611
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : April 9, 2026, 11:16 a.m. | 1 hour, 52 minutes ago
Description :Mattermost Plugins versions <=2.1.3.0 fail to limit the request body size on the {{/changes}} webhook endpoint which allows an authenticated attacker to cause memory exhaustion and denial of service via sending an oversized JSON payload. Mattermost Advisory ID: MMSA-2026-00611
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...