CVE-2024-52805
Last modified
CVE-2024-52805 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. EPSS estimates a 0.70% chance of exploitation in the next 30 days.
Description
Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Matrix | Synapse | < 1.120.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-52805?
How severe is CVE-2024-52805?
How do I fix CVE-2024-52805?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-5280The wp-affiliate-platform WordPress plugin before 6.5.1 does…4.7
- CVE-2024-52800veraPDF is an open source PDF/A validation library. Executin…2.3
- CVE-2024-52801sftpgo is a full-featured and highly configurable event-driv…5.3
- CVE-2024-52802RIOT is an operating system for internet of things (IoT) dev…7.5
- CVE-2024-52803LLama Factory enables fine-tuning of large language models. …9.8
- CVE-2024-52804Tornado is a Python web framework and asynchronous networkin…7.5
- CVE-2024-52806SimpleSAMLphp SAML2 library is a PHP library for SAML2 relat…8.3
- CVE-2024-52807The HL7 FHIR IG publisher is a tool to take a set of inputs …8.6
- CVE-2024-52809vue-i18n is an internationalization plugin for Vue.js. In a…5.3
- CVE-2024-5281The wp-affiliate-platform WordPress plugin before 6.5.1 does…6.1
- CVE-2024-52810@intlify/shared is a shared library for the intlify project.…6.9
- CVE-2024-52811The ngtcp2 project is an effort to implement IETF QUIC proto…8.2
Are you affected by CVE-2024-52805?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
