CVE-2024-52805

Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type.
Configurations

Configuration 1 (hide)

cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:*

History

26 Aug 2025, 15:06

Type Values Removed Values Added
CPE cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
Summary
  • (es) Synapse es un servidor doméstico Matrix de código abierto. En Synapse anterior a la versión 1.120.1, las solicitudes multipart/form-data pueden, en determinadas configuraciones, aumentar transitoriamente el consumo de memoria más allá de los niveles esperados mientras se procesa la solicitud, lo que se puede utilizar para amplificar los ataques de denegación de servicio. Synapse 1.120.1 resuelve el problema al denegar las solicitudes con un tipo de contenido multipart/form-data no compatible.
First Time Matrix synapse
Matrix
References () https://github.com/element-hq/synapse/security/advisories/GHSA-rfq8-j7rh-8hf2 - () https://github.com/element-hq/synapse/security/advisories/GHSA-rfq8-j7rh-8hf2 - Vendor Advisory
References () https://github.com/twisted/twisted/issues/4688#issuecomment-1167705518 - () https://github.com/twisted/twisted/issues/4688#issuecomment-1167705518 - Issue Tracking
References () https://github.com/twisted/twisted/issues/4688#issuecomment-2385711609 - () https://github.com/twisted/twisted/issues/4688#issuecomment-2385711609 - Issue Tracking

03 Dec 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-03 17:15

Updated : 2025-08-26 15:06


NVD link : CVE-2024-52805

Mitre link : CVE-2024-52805

CVE.ORG link : CVE-2024-52805


JSON object : View

Products Affected

matrix

  • synapse
CWE
CWE-770

Allocation of Resources Without Limits or Throttling