PT-2024-35455 · Synapse · Synapse
Published
2024-12-03
·
Updated
2025-08-26
·
CVE-2024-52805
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Synapse versions prior to 1.120.1
Description
The issue concerns Synapse, an open-source Matrix homeserver, where multipart/form-data requests can transiently increase memory consumption beyond expected levels in certain configurations, potentially amplifying denial of service attacks. This can be exploited to increase memory consumption while processing the request.
Recommendations
For Synapse versions prior to 1.120.1, update to Synapse 1.120.1 to resolve the issue, as it denies requests with unsupported multipart/form-data content type.
As a temporary workaround, consider limiting request sizes or blocking the
multipart/form-data content type before the requests reach Synapse, for example, in a reverse proxy.
Another approach to mitigate the attack is to use a low max upload size in Synapse.Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Synapse