Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Element-web sends tens of thousands of room key requests after login, effectively DoSsing a server #19488

Open
richvdh opened this issue Oct 23, 2021 · 0 comments
Labels
A-E2EE O-Occasional Affects or can be seen by some users regularly or most users rarely S-Major Severely degrades major functionality or product features, with no satisfactory workaround T-Defect

Comments

@richvdh
Copy link
Member

richvdh commented Oct 23, 2021

Steps to reproduce

matrix-org/synapse#11049 includes reports from a user whose server was effectively DoSed over a period of an hour, by a single element-desktop client sending room key requests. This apparently occurred during an attempt to log in:

image

Outcome

What did you expect?

Fewer room key requests.

What happened instead?

Tens of thousands of room key requests.

Operating system

No response

Application version

No response

How did you install the app?

No response

Homeserver

No response

Will you send logs?

No

@SimonBrandner SimonBrandner added A-E2EE S-Major Severely degrades major functionality or product features, with no satisfactory workaround labels Oct 24, 2021
@dbkr dbkr added the O-Occasional Affects or can be seen by some users regularly or most users rarely label Oct 25, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
A-E2EE O-Occasional Affects or can be seen by some users regularly or most users rarely S-Major Severely degrades major functionality or product features, with no satisfactory workaround T-Defect
Projects
None yet
Development

No branches or pull requests

3 participants