Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost to versions 10.11.0, 10.8.4, 10.5.9, 9.11.18, 10.10.2, 10.9.4 or higher.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29164 | Mattermost makes Use of Weak Hash |
Github GHSA |
GHSA-9p92-x77w-9fw2 | Mattermost makes Use of Weak Hash |
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Wed, 17 Sep 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost mattermost
|
|
| Vendors & Products |
Mattermost mattermost
|
Tue, 16 Sep 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost Server |
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost
Mattermost mattermost Server |
Mon, 15 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Sep 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.1, 10.9.x <= 10.9.3 fail to properly validate cache keys for link metadata which allows authenticated users to access unauthorized posts and poison link previews via hash collision attacks on FNV-1 hashing | |
| Title | Weak cache keys lead to post IDOR and link preview poisoning | |
| Weaknesses | CWE-328 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-09-15T13:57:49.086Z
Reserved: 2025-08-15T15:34:54.442Z
Link: CVE-2025-9078
Updated: 2025-09-15T13:53:39.946Z
Status : Analyzed
Published: 2025-09-15T10:15:32.627
Modified: 2025-09-16T15:58:12.830
Link: CVE-2025-9078
No data.
OpenCVE Enrichment
Updated: 2025-09-17T10:08:38Z
EUVD
Github GHSA