CVE-2026-2455 | Mattermost up to 10.11.10/11.2.2/11.3.0/11.3.x IPv6 Address server-side request forgery (EUVD-2026-12441)
A vulnerability was found in Mattermost up to 10.11.10/11.2.2/11.3.0/11.3.x. It has been classified as critical. Impacted is an unknown function of the component IPv6 Address Handler. Performing a manipulation results in server-side request forgery.
This vulnerability is cataloged as CVE-2026-2455. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.