CVE-2026-58270
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/09/2026
Last modified:
24/09/2026
Description
Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, the sync diff endpoint compiles a user-supplied string into a `RegExp` with no complexity validation. A catastrophic-backtracking pattern (e.g. `^(a+)+b`) blocks the Node.js event loop, making the entire server unresponsive to all users until the container is restarted. Version 2.4.0 patches the issue.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM


