445
VMScore

CVE-2020-26890

Published: 24/11/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Matrix Synapse prior to 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing remote malicious users to execute a denial of service attack against the federation and common Matrix clients. If such a malformed event is accepted into the room's state, the impact is long-lasting and is not fixed by an upgrade to a newer version, requiring the event to be manually redacted instead. Since events are replicated to servers of other room members, the impact is not constrained to the server of the event sender.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

matrix synapse

fedoraproject fedora 32

fedoraproject fedora 33

Vendor Advisories

A security issue was found in Synapse before 1200 A denial of service attack against Matrix clients could be performed by sending an event including invalid JSON data to Synapse Synapse would relay the data to clients which could crash or hang Impact is long-lasting if the event is made part of the room state ...