Stateward All advisories →
medium
CVE-2026-3590
Go · github.com/mattermost/mattermost/server/v8 • Go · github.com/mattermost/mattermost-server
Summary Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement
Severity medium EPSS 0.1% (p4) Also known as GHSA-mh4x-rmrx-3hp4#github.com/mattermost/mattermost-server, GHSA-mh4x-rmrx-3hp4#github.com/mattermost/mattermost/server/v8 Published 2026-04-17
Related advisories CVE-2026-6346 — high · Go/github.com/mattermost/mattermost/server/v8CVE-2026-3108 — high · Go/github.com/mattermost/mattermost/server/v8CVE-2026-6339 — medium · Go/github.com/mattermost/mattermost/server/v8CVE-2026-6343 — medium · Go/github.com/mattermost/mattermost/server/v8CVE-2026-5163 — medium · Go/github.com/mattermost/mattermost/server/v8CVE-2026-28732 — medium · Go/github.com/mattermost/mattermost/server/v8CVE-2026-6345 — medium · Go/github.com/mattermost/mattermost/server/v8CVE-2026-6340 — medium · Go/github.com/mattermost/mattermost/server/v8
Is your project exposed to this? Stateward checks every dependency on every pull request and flags it only if your code actually reaches it.
Check my repo