In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.
Start learningUpgrade matrix-synapse
to version 1.120.2 or higher.
matrix-synapse is an ecosystem for open federated Instant Messaging and VoIP.
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling due to the improper handling of multipart/form-data
content types. An attacker can amplify denial of service attacks by sending crafted requests that transiently increase memory consumption.
This vulnerability can be mitigated by limiting request sizes or blocking the multipart/form-data
content type before the requests reach the application, or by setting a low max_upload_size
.