CVE-2024-52805

Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type.
Configurations

Configuration 1 (hide)

cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:*

History

26 Aug 2025, 15:06

Type Values Removed Values Added
References () https://github.com/element-hq/synapse/security/advisories/GHSA-rfq8-j7rh-8hf2 - () https://github.com/element-hq/synapse/security/advisories/GHSA-rfq8-j7rh-8hf2 - Vendor Advisory
References () https://github.com/twisted/twisted/issues/4688#issuecomment-1167705518 - () https://github.com/twisted/twisted/issues/4688#issuecomment-1167705518 - Issue Tracking
References () https://github.com/twisted/twisted/issues/4688#issuecomment-2385711609 - () https://github.com/twisted/twisted/issues/4688#issuecomment-2385711609 - Issue Tracking
First Time Matrix synapse
Matrix
CPE cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

Information

Published : 2024-12-03 17:15

Updated : 2025-08-26 15:06


NVD link : CVE-2024-52805

Mitre link : CVE-2024-52805

CVE.ORG link : CVE-2024-52805


JSON object : View

Products Affected

matrix

  • synapse
CWE
CWE-770

Allocation of Resources Without Limits or Throttling