PyPi: Matrix-Synapse

CVE-2024-52805

Safety vulnerability ID: 74424

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Dec 03, 2024 Updated at Dec 11, 2024
Scan your Python projects for vulnerabilities →

Advisory

Affected versions of Synapse are vulnerable to allocation of resources without limits or throttling (CWE-770). An attacker can send crafted multipart/form-data requests that transiently increase memory consumption, leading to denial of service. The vulnerability is exploitable through multipart/form-data request processing configurations. Synapse version 1.120.1 mitigates the issue by denying unsupported multipart/form-data content types. To remediate, upgrade to 1.120.1 or limit request sizes and block multipart/form-data via a reverse proxy or by setting a low max_upload_size in Synapse.

Affected package

matrix-synapse

Latest version: 1.121.1

Homeserver for the Matrix decentralised comms protocol

Affected versions

Fixed versions

Vulnerability changelog

This vulnerability has no description

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application