Mattermost denial of service through long emoji value
        
  Moderate severity
        
          GitHub Reviewed
      
        Published
          Feb 29, 2024 
          to the GitHub Advisory Database
          •
          Updated Jan 10, 2025 
      
  
Package
Affected versions
>= 9.3.0, < 9.3.1
      >= 9.2.0, < 9.2.5
  Patched versions
9.3.1
      9.2.5
  Description
        Published by the National Vulnerability Database
      Feb 29, 2024 
    
  
        Published to the GitHub Advisory Database
      Feb 29, 2024 
    
  
        Reviewed
      Feb 29, 2024 
    
  
        Last updated
      Jan 10, 2025 
    
  
Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string as an emoji value causing high resource consumption and possibly crashing the server.
References