CVE-2024-36403 affects Matrix Media Repo (MMR) versions prior to 1.3.5, allowing an unauthenticated attacker to cause unbounded disk consumption by inducing the server to download and cache large remote media files. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity and no user interaction required, leading to a denial of service for file-backed storage or high service fees for cloud-based S3 storage. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE. While MMR 1.3.5 introduces a rate limit to mitigate the issue, operators should ensure proper X-Forwarded-For header configuration for reverse proxies.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.5CPE matchmatch criteria | cpe:2.3:a:t2bot:matrix-media-repo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.