CVE-2026-58270: Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters`

Published Sep 21, 2026
·
Updated

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, the sync diff endpoint compiles a user-supplied string into a RegExp with no complexity validation. A catastrophic-backtracking pattern (e.g. ^(a+)+b) blocks the Node.js event loop, making the entire server unresponsive to all users until the container is restarted. Version 2.4.0 patches the issue.

Affected Software

1 affected component
Sync-in Server<2.4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Sync-in Server to a version that resolves this vulnerability.

    Fixed in 2.4.0

Event History

Sep 21, 2026
CVE Published
via MITRE·08:28 PM
Data Sourced
via MITRE·08:28 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs low-privileged access to submit a request to the sync diff endpoint with a crafted pathFilters value. No user interaction is required.

2

What is the operational impact of successful exploitation?

A catastrophic-backtracking regular expression can block the Node.js event loop. This makes the entire server unresponsive to all users until the container is restarted.

3

Which deployments are affected?

Sync-in Server versions prior to 2.4.0 are affected if users with low privileges can reach the sync diff endpoint and supply pathFilters values.

4

What should be done if patching cannot happen immediately?

The provided information does not specify a workaround. Restricting access to the sync diff endpoint or preventing untrusted low-privileged users from supplying pathFilters may reduce exposure, but this is not documented as a complete mitigation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203