Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type.
Metrics
Affected Vendors & Products
References
History
Tue, 26 Aug 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Matrix
Matrix synapse |
|
CPEs | cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:* | |
Vendors & Products |
Matrix
Matrix synapse |
|
Metrics |
cvssV3_1
|
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 03 Dec 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Element-hq
Element-hq synapse |
|
CPEs | cpe:2.3:a:element-hq:synapse:*:*:*:*:*:*:*:* | |
Vendors & Products |
Element-hq
Element-hq synapse |
|
Metrics |
ssvc
|
Tue, 03 Dec 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type. | |
Title | Synapse allows unsupported content types to lead to memory exhaustion | |
Weaknesses | CWE-770 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-12-03T17:01:50.119Z
Updated: 2024-12-03T19:04:44.446Z
Reserved: 2024-11-15T17:11:13.442Z
Link: CVE-2024-52805

Updated: 2024-12-03T19:04:38.298Z

Status : Analyzed
Published: 2024-12-03T17:15:12.120
Modified: 2025-08-26T15:06:04.290
Link: CVE-2024-52805

No data.