CVE-2024-52805

Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type.
CVSS

No CVSS.

Configurations

No configuration.

History

03 Dec 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-03 17:15

Updated : 2024-12-03 17:15


NVD link : CVE-2024-52805

Mitre link : CVE-2024-52805

CVE.ORG link : CVE-2024-52805


JSON object : View

Products Affected

No product.

CWE
CWE-770

Allocation of Resources Without Limits or Throttling