VDB
Sign up
—

PYSEC-2026-1613

Synapse allows unsupported content types to lead to memory exhaustion

Quick fix

PYSEC-2026-1613 — matrix-synapse: upgrade to the fixed version with the command below.

pip install --upgrade 'matrix-synapse>=1.120.1'

Details

### Impact

In Synapse before 1.120.1, `multipart/form-data` requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks.

### Patches

Synapse 1.120.1 resolves the issue by denying requests with unsupported `multipart/form-data` content type.

### Workarounds

Limiting request sizes or blocking the `multipart/form-data` content type before the requests reach Synapse, for example in a reverse proxy, alleviates the issue. Another approach that mitigates the attack is to use a low `max_upload_size` in Synapse.

### References

- https://github.com/twisted/twisted/issues/4688#issuecomment-1167705518 - https://github.com/twisted/twisted/issues/4688#issuecomment-2385711609

### For more information

If you have any questions or comments about this advisory, please email us at [security at element.io](mailto:security@element.io).

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/matrix-synapse
Introduced in: 0Fixed in: 1.120.1
Fixpip install --upgrade 'matrix-synapse>=1.120.1'

References