MantisBT Vulnerable to Denial-of-Service (DoS) via Excessive Note Length
Description
Published to the GitHub Advisory Database
Nov 3, 2025
Reviewed
Nov 3, 2025
Published by the National Vulnerability Database
Nov 4, 2025
Last updated
Nov 4, 2025
A lack of server-side validation for note length in MantisBT allows attackers to permanently corrupt issue activity logs by submitting extremely long notes (tested with 4,788,761 characters). Once such a note is added:
Impact
Patches
Fixed in 2.27.2.
Workarounds
None
Credits
Thanks to Mazen Mahmoud (@TheAmazeng) for reporting the vulnerability.
References