CVE-2024-31208Medium· 6.5▾ SunlitSynapse V2 state resolution weakness allows Denial of Service (DoS)
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.5%
A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in how the auth chain cover index is calculated. This can induce high CPU consumption and accumulate excessive data in the database of such instances, resulting in a denial of service.
Servers in private federations, or those that do not federate, are not affected.
Server administrators should upgrade to 1.105.1 or later.
One can:
If you have any questions or comments about this advisory, please email us at security AT element.io.
matrix-synapse < 1.105.1Upgrade to a patched release:
matrix-synapse 1.105.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-45078Medium· 5.5Synapse CPU starvation (Denial of Service)
CVE-2026-45076MediumSynapse pagination Denial of Service
CVE-2024-53863HighSynapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
CVE-2025-30355High· 7.1Synapse vulnerable to federation denial of service via malformed events
CVE-2024-52805HighSynapse allows unsupported content types to lead to memory exhaustion
CVE-2025-61672MediumSynapse's invalid device keys degrade federation functionality