CVE-2026-5740: Unauthenticated WebSocket binary frame causes denial of service in Mattermost Server
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly validate msgpack-encoded WebSocket frames before memory allocation which allows an unauthenticated remote attacker to crash the server process and cause a full service outage for all users via a crafted binary WebSocket message sent to the public WebSocket endpoint.. Mattermost Advisory ID: MMSA-2026-00647
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5740?
The severity of CVE-2026-5740 is high with a score of 7.5.
What does CVE-2026-5740 affect?
CVE-2026-5740 affects Mattermost Server versions 11.6.x, 11.5.x, 11.4.x, and 10.11.x.
How do I fix CVE-2026-5740?
To fix CVE-2026-5740, update Mattermost to versions 11.7.0, 11.6.1, 11.5.4, 11.4.5, or 10.11.15 or higher.
What risk does CVE-2026-5740 pose?
CVE-2026-5740 poses a risk of denial of service due to improper validation of msgpack-encoded WebSocket frames.
Can CVE-2026-5740 be exploited remotely?
Yes, CVE-2026-5740 can be exploited by unauthenticated remote attackers.