Mattermost versions 8.1.x prior to 8.1.9, 9.2.x prior to 9.2.5, 9.3.0, and 9.4.x prior to 9.4.2 fail to limit the number of role names requested from the API, allowing an authenticated malicious user to cause the server to run out of memory and crash by issuing an unusually large HTTP request.