QID 982748

QID 982748: Python (pip) Security Update for matrix-sydent (GHSA-wmg4-8cp2-hpg9)

Security update has been released for matrix-sydent to fix the vulnerability.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Sydent does not limit the size of requests it receives from HTTP clients. A malicious user could send an HTTP request with a very large body, leading to disk space exhaustion and denial of service.

Sydent also does not limit response size for requests it makes to remote Matrix homeservers. A malicious homeserver could return a very large response, again leading to memory exhaustion and denial of service.

This affects any server which accepts registration requests from untrusted clients.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Patched by 89071a1, 0523511, f56eee3.Workaround:
    Request sizes can be limited in an HTTP reverse-proxy.

    There are no known workarounds for the problem with overlarge responses.
    Vendor References

    CVEs related to QID 982748

    Software Advisories
    Advisory ID Software Component Link
    GHSA-wmg4-8cp2-hpg9 matrix-sydent URL Logo github.com/advisories/GHSA-wmg4-8cp2-hpg9