VDB
KO
HIGH 7.5

GHSA-vmcc-4p4x-x7wg

Matrix Synapse DoS

Details

Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2<sup>63</sup> - 1 render rooms unusable, related to `federation/federation_base.py` and `handlers/message.py`, as exploited in the wild in April 2018.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / matrix-synapse
Introduced in: 0 Fixed in: 0.28.1
Fix pip install --upgrade 'matrix-synapse>=0.28.1'

References