VDB
GO-2025-3959
GO-2025-3959
PUBLISHED
Mattermost makes Use of Weak Hash in github.com/mattermost/mattermost-server
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | mattermost/mattermost-server/v5 | 0, 0 |
| github.com | mattermost/mattermost-server/v6 | 0, 0 |
| github.com | mattermost/mattermost/server/v8 | 0, 0 |
| github.com | mattermost/mattermost-server | 10.10.0+incompatible, 10.8.0+incompatible, 10.9.0+incompatible |
Timeline
- Sep 17, 2025 CVE Published
- Mar 3, 2026 CVE Updated
- May 1, 2026 Security Advisory
References
- https://github.com/advisories/GHSA-9p92-x77w-9fw2 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-9078 advisory
- https://mattermost.com/security-updates url
- https://github.com/mattermost/mattermost/commit/356880c8430b77a4a390c89d5a33f6928188d137 fix
- https://github.com/mattermost/mattermost/commit/944ad5cdd9876ef61c78c8275906262a4118755a fix
- https://github.com/mattermost/mattermost/commit/a8a4badc130be101e5bc4b7916bbcd2f966c4b79 fix
- https://github.com/mattermost/mattermost/commit/cd87e5c877373f109742aa90a3fa136c14774325 fix