-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from the original server ACL checking implementation in server_matches_acl_event, which processed allow/deny lists by converting glob patterns to regexes on every check. The commit f84da3c introduced caching and Rust-based pre-compilation, indicating the previous implementation lacked throttling/caching. The function was removed in the patch and replaced with a cached evaluator, confirming it was the source of the resource allocation vulnerability.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| matrix-synapse | pip | < 1.94.0 | 1.94.0 |
Ongoing coverage of React2Shell