#VU127002 Allocation of Resources Without Limits or Throttling in Synapse - CVE-2024-52805

 

#VU127002 Allocation of Resources Without Limits or Throttling in Synapse - CVE-2024-52805

Published: December 3, 2024 / Updated: April 23, 2026


Vulnerability identifier: #VU127002
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2024-52805
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Synapse
Software vendor:
Matrix.org

Description

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in multipart/form-data request handling when processing unsupported multipart/form-data requests. A remote attacker can send a specially crafted request to cause a denial of service.

Only certain configurations are vulnerable, and memory consumption may transiently increase beyond expected levels while the request is being processed.


Remediation

Install security update from vendor's website.

External links