#VU127002 Allocation of Resources Without Limits or Throttling in Synapse - CVE-2024-52805
Published: December 3, 2024 / Updated: April 23, 2026
Synapse
Matrix.org
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in multipart/form-data request handling when processing unsupported multipart/form-data requests. A remote attacker can send a specially crafted request to cause a denial of service.
Only certain configurations are vulnerable, and memory consumption may transiently increase beyond expected levels while the request is being processed.