{"id":"GHSA-7h5v-85w9-pq6c","aliases":[],"url":"https://o3.security/vulnerability/GHSA-7h5v-85w9-pq6c","summary":"Denial of service (via resource exhaustion) due to improper input validation in third-party identifier endpoint","details":"### Impact\nMissing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion.\n\n### Patches\nThe issue is fixed by https://github.com/matrix-org/synapse/pull/9855.\n\n### Workarounds\nThere are no known workarounds.\n\n### References\nn/a\n\n### For more information\nIf you have any questions or comments about this advisory, email us at security@matrix.org.\n","published":"2021-05-19T23:01:45Z","modified":"2024-12-02T05:59:59.340898Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"matrix-synapse","fixedVersion":"1.33.0"}],"fix":{"url":"https://github.com/matrix-org/synapse/pull/9855","label":"matrix-org/synapse#9855"},"references":[{"type":"WEB","url":"https://github.com/matrix-org/synapse/security/advisories/GHSA-7h5v-85w9-pq6c"},{"type":"WEB","url":"https://github.com/matrix-org/synapse/pull/9855"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-02T05:59:59.340898Z"}}