{"id":"GHSA-3cg3-3mmr-w8hj","summary":"Mattermost Confluence Plugin has Improper Validation of Specified Type of Input","details":"Mattermost Confluence Plugin versions \u003c 1.5.0 fail to handle unexpected request bodies, allowing attackers to crash the plugin via constant hits to the create channel subscription endpoint with an invalid request body.","aliases":["CVE-2025-54525","GO-2025-3872"],"modified":"2025-08-18T13:57:14.162605Z","published":"2025-08-11T21:31:40Z","database_specific":{"github_reviewed_at":"2025-08-12T00:07:04Z","nvd_published_at":"2025-08-11T19:15:30Z","cwe_ids":["CWE-1287"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54525"},{"type":"PACKAGE","url":"https://github.com/mattermost/mattermost-plugin-confluence"},{"type":"WEB","url":"https://mattermost.com/security-updates"}],"affected":[{"package":{"name":"github.com/mattermost/mattermost-plugin-confluence","ecosystem":"Go","purl":"pkg:golang/github.com/mattermost/mattermost-plugin-confluence"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.5.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-3cg3-3mmr-w8hj/GHSA-3cg3-3mmr-w8hj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}