Mattermost Server allows attackers to log sensitive information via DEBUG REST API logging endpoint in github.com/mattermost/mattermost-server
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2026-4299" }
"https://vuln.go.dev/ID/GO-2026-4299.json"