Skip to content

Denial of service (via resource exhaustion) due to improper input validation

Low
richvdh published GHSA-pw4v-gr34-2553 Apr 15, 2021

Package

pip matrix-sydent (pip)

Affected versions

<= 2.2.0

Patched versions

2.3.0

Description

Impact

Missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory leading to resource exhaustion.

Patches

Fixed by 3175fd3.

Workarounds

There are no known workarounds.

References

n/a

For more information

If you have any questions or comments about this advisory, email us at security@matrix.org.

Severity

Low

CVE ID

CVE-2021-29433

Weaknesses