{"id":"CVE-2018-16515","aliases":["GHSA-fmvh-rvq5-hhjx","PYSEC-2026-845"],"title":"Matrix Synapse Improper Signature Validation","summary":"Matrix Synapse Improper Signature Validation","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"matrix-synapse","product":"matrix-synapse","ecosystem":"pip","affected":["matrix-synapse >= 0.33.3, < 0.33.3.1","matrix-synapse < 0.33.2.1"],"patched":["matrix-synapse 0.33.3.1","matrix-synapse 0.33.2.1"],"published":"2022-05-13","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-fmvh-rvq5-hhjx","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-16515"},{"url":"https://github.com/matrix-org/synapse/issues/3796#event-1833126269"},{"url":"https://github.com/matrix-org/synapse/commit/5bf8bc79ebc22c61968f2eb487714813fccbdb9b"},{"url":"https://github.com/matrix-org/synapse/commit/804dd41e18c449e711e443398b95c9f6c68b6fa2"},{"url":"https://github.com/matrix-org/synapse/commit/a5a0bf5cf71caed3c4e3677d2bce667c147dadfc"},{"url":"https://github.com/matrix-org/synapse/commit/c127c8d0421f0228a46ebbe280c9537e8d8ea42b"},{"url":"https://github.com/matrix-org/synapse"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IRW7YR2H3ASUSYX4AO4KMY3FNVDNYW3P"},{"url":"https://matrix.org/blog/2018/09/06/critical-security-update-synapse-0-33-3-1"}],"tags":["osv","pip"],"epss":0.01359,"epssPercentile":0.70037,"ingestedAt":"2026-07-08T18:25:48.949Z","slug":"CVE-2018-16515","body":"## Overview\n\nMatrix Synapse before 0.33.3.1 and 0.33.2.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.\n\n## Affected packages\n\n- `matrix-synapse >= 0.33.3, < 0.33.3.1`\n- `matrix-synapse < 0.33.2.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `matrix-synapse 0.33.3.1`\n- `matrix-synapse 0.33.2.1`","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}