Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Ecosystem
Package
Version
Vulnerabilities
CVE-2025-12689
CVE-2025-12689
Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for proper UTF-8 format, which allows attacker to crash Calls plug-in via sending malformed request.
Published Dec 18, 2025
https://github.com/advisories/GHSA-j5vq-62gr-8v3r
CVSS Score
Medium
6.5
Components Impacted
Components Impacted
Security Details
Security Details
Sonatype Research
Sonatype Research
Ecosystem
Package
Version
Ecosystem
Package
Version
golang
github.com/mattermost/mattermost-plugin-calls
v0.10.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.11.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.12.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.12.1
golang
github.com/mattermost/mattermost-plugin-calls
v0.13.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.13.1
golang
github.com/mattermost/mattermost-plugin-calls
v0.14.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.14.1
golang
github.com/mattermost/mattermost-plugin-calls
v0.15.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.15.1
golang
github.com/mattermost/mattermost-plugin-calls
v0.15.2
golang
github.com/mattermost/mattermost-plugin-calls
v0.15.3
golang
github.com/mattermost/mattermost-plugin-calls
v0.15.4
golang
github.com/mattermost/mattermost-plugin-calls
v0.16.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.16.1
golang
github.com/mattermost/mattermost-plugin-calls
v0.17.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.17.1
golang
github.com/mattermost/mattermost-plugin-calls
v0.18.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.18.1
golang
github.com/mattermost/mattermost-plugin-calls
v0.18.2
golang
github.com/mattermost/mattermost-plugin-calls
v0.19.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.19.1
golang
github.com/mattermost/mattermost-plugin-calls
v0.19.2
golang
github.com/mattermost/mattermost-plugin-calls
v0.2.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.20.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.21.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.21.1
golang
github.com/mattermost/mattermost-plugin-calls
v0.22.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.22.1
golang
github.com/mattermost/mattermost-plugin-calls
v0.22.2
golang
github.com/mattermost/mattermost-plugin-calls
v0.23.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.23.1
golang
github.com/mattermost/mattermost-plugin-calls
v0.24.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.25.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.25.1
golang
github.com/mattermost/mattermost-plugin-calls
v0.26.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.26.1
golang
github.com/mattermost/mattermost-plugin-calls
v0.26.2
golang
github.com/mattermost/mattermost-plugin-calls
v0.27.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.28.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.28.1
golang
github.com/mattermost/mattermost-plugin-calls
v0.28.2
golang
github.com/mattermost/mattermost-plugin-calls
v0.29.0
golang
github.com/mattermost/mattermost-plugin-calls
v0.29.1
golang
github.com/mattermost/mattermost-plugin-calls
v0.29.2
golang
github.com/mattermost/mattermost-plugin-calls
v0.29.3
golang
github.com/mattermost/mattermost-plugin-calls
v0.29.4
golang
github.com/mattermost/mattermost-plugin-calls
v0.29.5
golang
github.com/mattermost/mattermost-plugin-calls
v0.29.6
golang
github.com/mattermost/mattermost-plugin-calls
v0.29.7
1-50 of 94
CVE-2025-12689 | Components Impacted | Sonatype Guide | Sonatype Guide