Missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion.
The issue is fixed by https://github.com/matrix-org/synapse/pull/9855.
There are no known workarounds.
n/a
If you have any questions or comments about this advisory, email us at security@matrix.org.
{
"severity": "MODERATE",
"cwe_ids": [
"CWE-400"
],
"github_reviewed_at": "2021-05-19T19:34:56Z",
"github_reviewed": true,
"nvd_published_at": null
}