PT-2026-96250 · Unknown · @Sync-In/Server

CVE-2026-58270

·

Published

2026-09-21

·

Updated

2026-09-22

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Sync-in Server versions prior to 2.4.0
Description Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. The sync diff endpoint POST /api/app/sync/operation/diff/:id compiles a user-supplied string provided via the pathFilters variable into a RegExp without complexity validation. This allows an authenticated user to submit a catastrophic-backtracking pattern (such as ^(a+)+b), which is a regular expression that takes an exponential amount of time to process certain inputs. Because the .test() function is executed synchronously, this blocks the Node.js event loop, causing the entire server to become unresponsive to all users and potentially requiring a container restart to restore service.
Recommendations Update Sync-in Server to version 2.4.0. As a temporary workaround, restrict the use of the pathFilters variable in the POST /api/app/sync/operation/diff/:id endpoint.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58270
GHSA-JX63-H26R-8CPH

Affected Products

@Sync-In/Server