7zip Upload Causing Memory Exhaustion in Mattermost 10.11.13, 11.4.3, 11.5.1
CVE-2026-6340 Published on May 18, 2026

Memory Exhaustion via Malicious 7zip File Upload
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate 7zip archive structure before processing which allows an authenticated attacker to cause server memory exhaustion and denial of service via uploading a specially crafted 7zip file with excessive folder declarations.. Mattermost Advisory ID: MMSA-2026-00573

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-6340 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a small impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
NONE
Availability Impact:
LOW

Weakness Type

What is a Stack Exhaustion Vulnerability?

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

CVE-2026-6340 has been classified to as a Stack Exhaustion vulnerability or weakness.


Products Associated with CVE-2026-6340

Want to know whenever a new CVE is published for MatterMost? stack.watch will email you.

 

Affected Versions

Mattermost: