CVE-2024-53867Medium· 4.3▾ SunlitSynapse Matrix has a partial room state leak via Sliding Sync
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
0.4% → 0.4%
The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room. Non-state events, like messages, are unaffected.
Synapse version 1.120.1 fixes the problem.
Disable Sliding Sync.
https://github.com/matrix-org/matrix-spec-proposals/pull/4186 https://github.com/element-hq/synapse/blob/d80cd57c54427687afcb48740d99219c88a0fff1/synapse/config/experimental.py#L341-L344
If you have any questions or comments about this advisory, please email us at security at element.io.
matrix-synapse >= 1.113.0rc1, < 1.120.1Upgrade to a patched release:
matrix-synapse 1.120.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-45078Medium· 5.5Synapse CPU starvation (Denial of Service)
CVE-2026-45076MediumSynapse pagination Denial of Service
CVE-2024-31208Medium· 6.5Synapse V2 state resolution weakness allows Denial of Service (DoS)
CVE-2024-53863HighSynapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
CVE-2025-30355High· 7.1Synapse vulnerable to federation denial of service via malformed events
CVE-2024-52805HighSynapse allows unsupported content types to lead to memory exhaustion