Mattermost doesn't validate the response body of proxied images
Moderate severity
GitHub Reviewed
Published
May 15, 2026
to the GitHub Advisory Database
•
Updated May 28, 2026
Package
Affected versions
>= 11.5.0, < 11.5.2
>= 0.0.0-20250731163400-5b955468ea1e, < 0.0.0-20260414103857-b21ef302025e
>= 11.4.0, < 11.4.4
Patched versions
11.5.2
0.0.0-20260414103857-b21ef302025e
11.4.4
Description
Published by the National Vulnerability Database
May 15, 2026
Published to the GitHub Advisory Database
May 15, 2026
Reviewed
May 28, 2026
Last updated
May 28, 2026
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate the response body of proxied images, which allows a remote attacker to enact client-side DoS via an SVG file served from an attacker-controlled origin under a non-SVG Content-Type header (e.g. image/png) embedded in an og:image meta tag or Markdown image link. Mattermost Advisory ID: MMSA-2026-00630.
References