CVE-2026-58270

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/09/2026
Last modified:
24/09/2026

Description

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, the sync diff endpoint compiles a user-supplied string into a `RegExp` with no complexity validation. A catastrophic-backtracking pattern (e.g. `^(a+)+b`) blocks the Node.js event loop, making the entire server unresponsive to all users until the container is restarted. Version 2.4.0 patches the issue.