HIGH🇵🇱 Wersja polska

CVE-2024-52805

CVSS 8.2v4.0pub. 2024-12-03upd. 2025-08-26

Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Matrix Synapse

    APP
    Matrix
    < 1.120.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2019-18835CRITICAL9.8PL ✓same product

Matrix Synapse: błąd weryfikacji podpisów w federation API

CVE-2025-30355HIGH7.1same product

Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when re...

CVE-2024-53863HIGH8.2same product

Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnai...

CVE-2024-37302HIGH7.5same product

Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attac...

CVE-2024-52815HIGH8.7same product

Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites...