CVE-2026-58270: Sync-In Server
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, the sync diff endpoint compiles a user-supplied string into a `RegExp` with no complexity validation. A catastrophic-backtracking pattern (e.g. `^(a+)+b`) blocks the Node.js event loop, making the entire server unresponsive to all users until the container is restarted. Version 2.4.0 patches the issue.
Affected products
- Sync-In Server: before 2.4.0 (fixed in 2.4.0)
Published 2026-09-21. Last modified 2026-09-24.