PT-2024-35455 · Synapse · Synapse

Published

2024-12-03

·

Updated

2025-08-26

·

CVE-2024-52805

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Synapse versions prior to 1.120.1
Description The issue concerns Synapse, an open-source Matrix homeserver, where multipart/form-data requests can transiently increase memory consumption beyond expected levels in certain configurations, potentially amplifying denial of service attacks. This can be exploited to increase memory consumption while processing the request.
Recommendations For Synapse versions prior to 1.120.1, update to Synapse 1.120.1 to resolve the issue, as it denies requests with unsupported multipart/form-data content type. As a temporary workaround, consider limiting request sizes or blocking the multipart/form-data content type before the requests reach Synapse, for example, in a reverse proxy. Another approach to mitigate the attack is to use a low max upload size in Synapse.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-52805
GHSA-RFQ8-J7RH-8HF2
OPENSUSE-SU-2024:14541-1

Affected Products

Synapse