<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T20:05:49.228267+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2024-52805</id>
    <title>CVE-2024-52805 — Synapse allows unsupported content types to lead to memory exhaustion</title>
    <updated>2026-10-03T20:05:49.230122+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> element-hq synapse</p>
<p>Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2024-52805"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-rfq8-j7rh-8hf2</id>
    <title>GHSA-rfq8-j7rh-8hf2 — Synapse allows unsupported content types to lead to memory exhaustion</title>
    <updated>2026-10-03T20:05:49.230188+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: matrix-synapse</p>
<p>### Impact</p>
<p>In Synapse before 1.120.1, `multipart/form-data` requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks.</p>
<p>### Patches</p>
<p>Synapse 1.120.1 resolves the issue by denying requests with unsupported `multipart/form-data` content type.</p>
<p>### Workarounds</p>
<p>Limiting request sizes or blocking the `multipart/form-data` content type before the requests reach Synapse, for example in a reverse proxy, alleviates the issue. Another approach that mitigates the attack is to use a low `max_upload_size` in Synapse.</p>
<p>### References</p>
<p>- https://github.com/twisted/twisted/issues/4688#issuecomment-1167705518
- https://github.com/twisted/twisted/issues/4688#issuecomment-2385711609</p>
<p>### For more information</p>
<p>If you have any questions or comments about this advisory, please email us at [security at element.io](mailto:security@element.io).</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-rfq8-j7rh-8hf2"/>
  </entry>
</feed>
