CVE-2020-26257Medium· 6.5▾ SunlitDenial of service attack via incorrect parameters in Matrix Synapse
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
2.4%
A malicious or poorly-implemented homeserver can inject malformed events into a room by specifying a different room id in the path of a /send_join, /send_leave, /invite or /exchange_third_party_invite request.
This can lead to a denial of service in which future events will not be correctly sent to other servers over federation.
This affects any server which accepts federation requests from untrusted servers.
Issue is resolved by https://github.com/matrix-org/synapse/pull/8776.
Homeserver administrators could limit access to the federation API to trusted servers (for example via federation_domain_whitelist).
matrix-synapse < 1.23.1Upgrade to a patched release:
matrix-synapse 1.23.1Connected by shared product, vendor, weakness, or advisory.
CVE-2023-43796Medium· 5.3Synapse vulnerable to leak of remote user device information
CVE-2026-45078Medium· 5.5Synapse CPU starvation (Denial of Service)
CVE-2023-42453Low· 3.1matrix-synapse vulnerable to improper validation of receipts allows forged read receipts
CVE-2026-45076MediumSynapse pagination Denial of Service
CVE-2023-45129Medium· 4.9matrix-synapse vulnerable to denial of service due to malicious server ACL events
CVE-2023-41335Low· 3.7matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes