CVE-2022-3147: low-severity vulnerability in Mattermost
Server-side Denial of Service while processing a specifically crafted JPEG file
Published · Updated
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 3.1epss 1.0%
exploitation probability
1.0%top 37% of all CVEs
observed exploitation
nono source reports it
Mattermost version 7.0.x and earlier fails to sufficiently limit the in-memory sizes of concurrently uploaded JPEG images, which allows authenticated users to cause resource exhaustion on specific system configurations, resulting in server-side Denial of Service.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
Affected products
Mattermost · MattermostRelated CVEs — Mattermost
In the same product, most dangerous first.
CVE-2025-25279CRITICALArbitrary file read in Mattermost Boards via import & export board archiveEPSS 24.2%CVE-2021-37859HIGHReflected XSS in OAuth FlowEPSS 3.3%CVE-2022-3257LOWServer-side Denial of Service while processing a specifically crafted GIF fileEPSS 1.3%CVE-2022-4044MEDIUMAuthenticated user could send multiple requests containing a large Auto Responder Message payload and can crash a Mattermost serverEPSS 1.1%CVE-2022-1982MEDIUMA crafted SVG attachment can crash a Mattermost serverEPSS 0.9%CVE-2022-0904MEDIUMStack overflow in document extractor in MattermostEPSS 0.9%