CVE-2021-29430 is a denial-of-service vulnerability affecting Sydent, the reference Matrix identity server. It allows attackers to cause memory exhaustion by sending oversized HTTP requests or by tricking Sydent into processing oversized responses from malicious Matrix homeservers. This vulnerability has a CVSS score of 7.5 (High), indicating it can be exploited remotely with low complexity and no user interaction, leading to a complete loss of availability. While patches are available, there are no known workarounds for oversized responses, and there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.0CPE matchmatch criteria | cpe:2.3:a:matrix:sydent:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.