CVE-2021-21274
Python vulnerability analysis and mitigation

Overview

Synapse, a Matrix reference homeserver written in python (pypi package matrix-synapse), was found to be vulnerable to a denial of service attack via .well-known lookups. The vulnerability (CVE-2021-21274) affected versions above 0.99.0 and was patched in version 1.25.0. This security issue was discovered in February 2021 and impacted servers that accept federation requests from untrusted servers (GitHub Advisory).

Technical details

A malicious homeserver could redirect requests to their .well-known file to a large file, causing the requesting server to consume significantly more resources when processing the .well-known file. The issue was resolved by implementing a maximum size limit of 50 kilobytes for .well-known lookups (GitHub PR).

Impact

The vulnerability could lead to a denial of service attack where homeservers would consume significantly more resources when requesting the .well-known file of a malicious homeserver. This affected any server which accepts federation requests from untrusted servers (GitHub Advisory).

Exploitability

The vulnerability was rated as Low severity. It required a malicious actor to control a homeserver that could be federated with the target server. The attack could be executed remotely without requiring authentication (GitHub Advisory).

Mitigation and workarounds

The vulnerability was patched in version 1.25.0. As a workaround before updating, administrators could use the federation_domain_whitelist setting to restrict the homeservers communicated with over federation (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84366HIGH7.4
  • Python logoPython
  • scrapy
NoYesSep 01, 2026
CVE-2026-53720MEDIUM5.1
  • Python logoPython
  • pymonocypher
NoYesSep 03, 2026
CVE-2026-84311MEDIUM4.8
  • Python logoPython
  • pypdf
NoYesSep 01, 2026
CVE-2026-84310MEDIUM4.8
  • Python logoPython
  • pypdf
NoYesSep 01, 2026
GHSA-wwv5-g3v4-889xLOW2.3
  • Python logoPython
  • tornado
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management