PT-2026-96250 · Unknown · @Sync-In/Server
CVE-2026-58270
·
Published
2026-09-21
·
Updated
2026-09-22
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Sync-in Server versions prior to 2.4.0
Description
Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. The sync diff endpoint
POST /api/app/sync/operation/diff/:id compiles a user-supplied string provided via the pathFilters variable into a RegExp without complexity validation. This allows an authenticated user to submit a catastrophic-backtracking pattern (such as ^(a+)+b), which is a regular expression that takes an exponential amount of time to process certain inputs. Because the .test() function is executed synchronously, this blocks the Node.js event loop, causing the entire server to become unresponsive to all users and potentially requiring a container restart to restore service.Recommendations
Update Sync-in Server to version 2.4.0.
As a temporary workaround, restrict the use of the
pathFilters variable in the POST /api/app/sync/operation/diff/:id endpoint.Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Sync-In/Server