CVE-2021-29430High· 7.5▾ TwilightSydent vulnerable to denial of service attack via memory exhaustion
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.8%
Sydent does not limit the size of requests it receives from HTTP clients. A malicious user could send an HTTP request with a very large body, leading to disk space exhaustion and denial of service.
Sydent also does not limit response size for requests it makes to remote Matrix homeservers. A malicious homeserver could return a very large response, again leading to memory exhaustion and denial of service.
This affects any server which accepts registration requests from untrusted clients.
Patched by 89071a1, 0523511, f56eee3.
Request sizes can be limited in an HTTP reverse-proxy.
There are no known workarounds for the problem with overlarge responses.
If you have any questions or comments about this advisory, email us at [email protected].
matrix-sydent < 2.3.0Upgrade to a patched release:
matrix-sydent 2.3.0Connected by shared product, vendor, weakness, or advisory.
CVE-2021-29431High· 7.7SSRF in Sydent due to missing validation of hostnames
CVE-2021-29433Medium· 4.3Sydent DoS (via resource exhaustion) due to improper input validation
CVE-2021-29432Medium· 5.3Malicious users could abuse Sydent to control the content of invitation emails
CVE-2023-38686Critical· 9.3Sydent does not verify email server certificates
CVE-2019-11842High· 7.5matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG
CVE-2019-11340Medium· 5.9Matrix Sydent mishandles emails