A lack of server-side validation for note length in MantisBT allows attackers to permanently corrupt issue activity logs by submitting extremely long notes (tested with 4,788,761 characters). Once such a note is added:
Fixed in 2.27.2.
None
Thanks to Mazen Mahmoud (@TheAmazeng) for reporting the vulnerability.
{
"cwe_ids": [
"CWE-770"
],
"github_reviewed": true,
"nvd_published_at": "2025-11-04T01:15:33Z",
"severity": "MODERATE",
"github_reviewed_at": "2025-11-03T17:07:39Z"
}