Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost to versions 10.11.0, 10.8.4, 10.5.9, 9.11.18, 10.10.1, 10.9.4 or higher.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-25459 | Mattermost has Potential Server Crash due to Unvalidated Import Data |
Github GHSA |
GHSA-h469-4fcf-p23h | Mattermost has Potential Server Crash due to Unvalidated Import Data |
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Wed, 01 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost mattermost Server
|
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.10.0:-:*:*:*:*:*:* |
|
| Vendors & Products |
Mattermost mattermost Server
|
Sat, 23 Aug 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Thu, 21 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 21 Aug 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to validate import data which allows a system admin to crash the server via the bulk import feature. | |
| Title | Nil pointer dereference in bulk import crashes server | |
| Weaknesses | CWE-1287 CWE-476 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-08-21T17:30:38.422Z
Reserved: 2025-07-31T00:31:47.312Z
Link: CVE-2025-8402
Updated: 2025-08-21T17:20:46.523Z
Status : Analyzed
Published: 2025-08-21T17:15:33.093
Modified: 2025-10-01T20:23:12.900
Link: CVE-2025-8402
No data.
OpenCVE Enrichment
Updated: 2025-08-23T10:55:38Z
EUVD
Github GHSA