CVE-2025-35965
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 770
Summary
CVE-2025-35965 is a vulnerability affecting Mattermost versions 10.4.x through 10.4.2, 10.5.x through 10.5.0, and 9.11.x through 9.11.10. This issue arises from a failure to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation. An attacker can exploit this by creating task items with an excessive number of actions, triggered by specific posts. This leads to a denial-of-service (DoS) condition as the server becomes overwhelmed, unable to process the excessive data.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mattermost Server
Affected Vendors
- Mattermost