CVE-2024-52805

Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type.
Configurations

Configuration 1 (hide)

cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:*

History

26 Aug 2025, 15:06

Type Values Removed Values Added
First Time Matrix
Matrix synapse
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:*
References () https://github.com/element-hq/synapse/security/advisories/GHSA-rfq8-j7rh-8hf2 - () https://github.com/element-hq/synapse/security/advisories/GHSA-rfq8-j7rh-8hf2 - Vendor Advisory
References () https://github.com/twisted/twisted/issues/4688#issuecomment-1167705518 - () https://github.com/twisted/twisted/issues/4688#issuecomment-1167705518 - Issue Tracking
References () https://github.com/twisted/twisted/issues/4688#issuecomment-2385711609 - () https://github.com/twisted/twisted/issues/4688#issuecomment-2385711609 - Issue Tracking

03 Dec 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-03 17:15

Updated : 2025-08-26 15:06


NVD link : CVE-2024-52805

Mitre link : CVE-2024-52805

CVE.ORG link : CVE-2024-52805


JSON object : View

Products Affected

matrix

  • synapse
CWE
CWE-770

Allocation of Resources Without Limits or Throttling