CVE-2024-52805: Synapse allows unsupported content types to lead to memory exhaustion
In Synapse before 1.120.1, multipart/form-data
requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks.
References
Detect and mitigate CVE-2024-52805 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →