matrix-synapse is vulnerable to Uncontrolled Resource Consumption
75
High Risk
Synapse's existing mitigation against malicious multipart/form-data requests performs a case-sensitive check on the Content-Type header. By varying the case of the header, a client can bypass the mitigation. A crafted request then causes Synapse to rapidly exhaust all available memory and become unresponsive or be terminated, denying service to other users. The fix makes the content-type check case-insensitive.
You are affected if you are using a version that falls within the vulnerable range.
matrix-synapse is vulnerable to Uncontrolled Resource Consumption in versions 0.0.1 - 1.157.1.
Upgrade the matrix-synapse library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant