Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type.
Metrics
Affected Vendors & Products
References
History
Tue, 03 Dec 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Element-hq
Element-hq synapse |
|
CPEs | cpe:2.3:a:element-hq:synapse:*:*:*:*:*:*:*:* | |
Vendors & Products |
Element-hq
Element-hq synapse |
|
Metrics |
ssvc
|
Tue, 03 Dec 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type. | |
Title | Synapse allows unsupported content types to lead to memory exhaustion | |
Weaknesses | CWE-770 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-03T19:04:44.446Z
Reserved: 2024-11-15T17:11:13.442Z
Link: CVE-2024-52805

Updated: 2024-12-03T19:04:38.298Z

Status : Received
Published: 2024-12-03T17:15:12.120
Modified: 2024-12-03T17:15:12.120
Link: CVE-2024-52805

No data.