VYPR
Medium severity6.5NVD Advisory· Published Sep 21, 2026

CVE-2026-58270

CVE-2026-58270

Description

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, the sync diff endpoint compiles a user-supplied string into a RegExp with no complexity validation. A catastrophic-backtracking pattern (e.g. ^(a+)+b) blocks the Node.js event loop, making the entire server unresponsive to all users until the container is restarted. Version 2.4.0 patches the issue.

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.