Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type.
Metrics
Affected Vendors & Products
References
History
Tue, 26 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Matrix
Matrix synapse |
|
| CPEs | cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Matrix
Matrix synapse |
|
| Metrics |
cvssV3_1
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 03 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Element-hq
Element-hq synapse |
|
| CPEs | cpe:2.3:a:element-hq:synapse:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Element-hq
Element-hq synapse |
|
| Metrics |
ssvc
|
Tue, 03 Dec 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type. | |
| Title | Synapse allows unsupported content types to lead to memory exhaustion | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-12-03T17:01:50.119Z
Updated: 2024-12-03T19:04:44.446Z
Reserved: 2024-11-15T17:11:13.442Z
Link: CVE-2024-52805
Updated: 2024-12-03T19:04:38.298Z
Status : Analyzed
Published: 2024-12-03T17:15:12.120
Modified: 2025-08-26T15:06:04.290
Link: CVE-2024-52805
No data.