matrix-synapse is vulnerable to Uncontrolled Resource Consumption
77
High Risk
Synapse lets users configure push rules without any server-side limit on their number or total size. Stored push rules are loaded back into memory when fetched and when processing push rules for new events. A local user can register a very large volume of push rules, exhausting disk space and memory and denying service to other users. The fix enforces server-side size and count limits on push rules.
You are affected if you are using a version that falls within the vulnerable range and your homeserver allows untrusted local users.
matrix-synapse is vulnerable to Uncontrolled Resource Consumption in versions 0.0.1 - 1.157.1.
Upgrade the matrix-synapse library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant