Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3505 | Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type. |
Github GHSA |
GHSA-rfq8-j7rh-8hf2 | Synapse allows unsupported content types to lead to memory exhaustion |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 26 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Matrix
Matrix synapse |
|
| CPEs | cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Matrix
Matrix synapse |
|
| Metrics |
cvssV3_1
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 03 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Element-hq
Element-hq synapse |
|
| CPEs | cpe:2.3:a:element-hq:synapse:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Element-hq
Element-hq synapse |
|
| Metrics |
ssvc
|
Tue, 03 Dec 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type. | |
| Title | Synapse allows unsupported content types to lead to memory exhaustion | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-03T19:04:44.446Z
Reserved: 2024-11-15T17:11:13.442Z
Link: CVE-2024-52805
Updated: 2024-12-03T19:04:38.298Z
Status : Analyzed
Published: 2024-12-03T17:15:12.120
Modified: 2025-08-26T15:06:04.290
Link: CVE-2024-52805
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA