CVE-2026-10819: Mattermost Server Denial of Service via Animated GIF Emoji Upload
Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 11.8.1, 11.7.x <= 11.7.4 fail to limit the number of frames and enforce the file size cap on animated GIF uploads, which allows an authenticated attacker to cause a denial of service via a crafted animated GIF uploaded as a custom emoji.. Mattermost Advisory ID: MMSA-2026-00695
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mattermost Serverto a version that resolves this vulnerability.Fixed in 11.9.0 - Upgrade
Upgrade
Mattermost Serverto a version that resolves this vulnerability.Fixed in 11.6.6 - Upgrade
Upgrade
Mattermost Serverto a version that resolves this vulnerability.Fixed in 10.11.21 - Upgrade
Upgrade
Mattermost Serverto a version that resolves this vulnerability.Fixed in 11.8.2 - Upgrade
Upgrade
Mattermost Serverto a version that resolves this vulnerability.Fixed in 11.7.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MMSA-2026-00695
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10819?
CVE-2026-10819 has a medium severity rating of 6.5.
How do I fix CVE-2026-10819?
To fix CVE-2026-10819, upgrade your Mattermost Server to a version that addresses this vulnerability.
What attack vector is involved in CVE-2026-10819?
CVE-2026-10819 involves an authenticated attacker uploading a crafted animated GIF that leads to a denial of service.
Which Mattermost versions are affected by CVE-2026-10819?
Mattermost versions 11.6.x up to 11.6.5, 10.11.x up to 10.11.20, 11.8.x up to 11.8.1, and 11.7.x up to 11.7.4 are affected by CVE-2026-10819.
What is the impact of CVE-2026-10819?
The impact of CVE-2026-10819 is a denial of service due to the lack of limits on animated GIF uploads.