GHSA-rfq8-j7rh-8hf2 · Severity: high · Ecosystem: pip — Synapse allows unsupported content types to lead to memory exhaustion
Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type.
Conclusion & alert: CVE-2024-52805 is rated Moderate Risk (49.3/100): CVSS High severity, with low exploitation likelihood (EPSS 0.70%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 1.09% | 0.70% | -0.39% |
| 2 | 2026-05-23 | 0.84% | 1.09% | +0.25% |
| 3 | 2026-03-23 | — | 0.84% | — |
Full EPSS history (13 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.2 | 4.0 | HIGH |
|
— | — | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
GHSA-rfq8-j7rh-8hf2 · Severity: high · Ecosystem: pip — Synapse allows unsupported content types to lead to memory exhaustion
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2024-52805: 1 source package rows (synapse); 40 state rows across 4 repos (3.20-community, 3.21-community, 3.22-community, edge-community); fixed 4, open 36. | https://security.alpinelinux.org/vuln/CVE-2024-52805 |
debian
|
not yet assigned | CVE-2024-52805 not yet assigned priority: Debian including 1 source packages (matrix-synapse), 2 status rows across 2 suites (forky, sid): resolved 2. | https://security-tracker.debian.org/tracker/CVE-2024-52805 |
ubuntu
|
medium | CVE-2024-52805 medium priority: Ubuntu including 1 source packages (matrix-synapse), 6 status rows across 6 suites (bionic, focal, jammy, noble, oracular, upstream): deferred 4, ignored 1, released 1. | https://ubuntu.com/security/CVE-2024-52805 |
| URL | Tags |
|---|---|
| https://github.com/element-hq/synapse/security/advisories/GHSA-rfq8-j7rh-8hf2 | Vendor Advisory |
| https://github.com/twisted/twisted/issues/4688#issuecomment-1167705518 | Issue Tracking |
| https://github.com/twisted/twisted/issues/4688#issuecomment-2385711609 | Issue Tracking |