CVE-2025-35965

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 770

Summary

CVE-2025-35965 is a vulnerability affecting Mattermost versions 10.4.x through 10.4.2, 10.5.x through 10.5.0, and 9.11.x through 9.11.10. This issue arises from a failure to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation. An attacker can exploit this by creating task items with an excessive number of actions, triggered by specific posts. This leads to a denial-of-service (DoS) condition as the server becomes overwhelmed, unable to process the excessive data.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mattermost Server

Affected Vendors

  • Mattermost