CVE-2024-52805: Synapse allows unsupported content types to lead to memory exhaustion
In Synapse before 1.120.1, multipart/form-data
requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks.
References
Code Behaviors & Features
Detect and mitigate CVE-2024-52805 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →