VulnSea

matrix-synapse vulnerabilities

CVEs whose affected-version data names the matrix-synapse package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

34 CVEsRSS

CVE-2026-45078Medium· 5.5
4mo ago

Synapse CPU starvation (Denial of Service)

Synapse CPU starvation (Denial of Service)

Sunlitmatrix-synapse · matrix-synapseEPSS 0.13%via OSV
CVE-2026-45076Medium
4mo ago

Synapse pagination Denial of Service

Synapse pagination Denial of Service

Sunlitmatrix-synapse · matrix-synapseEPSS 0.37%via OSV
CVE-2025-61672Medium
11mo ago

Synapse's invalid device keys degrade federation functionality

Synapse's invalid device keys degrade federation functionality

Sunlitmatrix-synapse · matrix-synapseEPSS 0.47%via OSV
CVE-2025-30355High· 7.1
1y ago

Synapse vulnerable to federation denial of service via malformed events

Synapse vulnerable to federation denial of service via malformed events

Twilightmatrix-synapse · matrix-synapseEPSS 1.2%via OSV
CVE-2024-53863High
1y ago

Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders

Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders

Twilightmatrix-synapse · matrix-synapseEPSS 0.61%via OSV
CVE-2024-52805High
1y ago

Synapse allows unsupported content types to lead to memory exhaustion

Synapse allows unsupported content types to lead to memory exhaustion

Twilightmatrix-synapse · matrix-synapseEPSS 0.74%via OSV
CVE-2024-52815High
1y ago

Synapse allows a a malformed invite to break the invitee's `/sync`

Synapse allows a a malformed invite to break the invitee's `/sync`

Twilightmatrix-synapse · matrix-synapseEPSS 0.57%via OSV
CVE-2024-53867Medium· 4.3
1y ago

Synapse Matrix has a partial room state leak via Sliding Sync

Synapse Matrix has a partial room state leak via Sliding Sync

Sunlitmatrix-synapse · matrix-synapseEPSS 0.44%via OSV
CVE-2024-31208Medium· 6.5
2y ago

Synapse V2 state resolution weakness allows Denial of Service (DoS)

Synapse V2 state resolution weakness allows Denial of Service (DoS)

Sunlitmatrix-synapse · matrix-synapseEPSS 1.5%via OSV
CVE-2023-43796Medium· 5.3
2y ago

Synapse vulnerable to leak of remote user device information

Synapse vulnerable to leak of remote user device information

Sunlitmatrix-synapse · matrix-synapseEPSS 0.90%via OSV
CVE-2023-45129Medium· 4.9
2y ago

matrix-synapse vulnerable to denial of service due to malicious server ACL events

matrix-synapse vulnerable to denial of service due to malicious server ACL events

Sunlitmatrix-synapse · matrix-synapseEPSS 1.2%via OSV
CVE-2023-42453Low· 3.1
2y ago

matrix-synapse vulnerable to improper validation of receipts allows forged read receipts

matrix-synapse vulnerable to improper validation of receipts allows forged read receipts

Sunlitmatrix-synapse · matrix-synapseEPSS 0.65%via OSV
CVE-2023-41335Low· 3.7
2y ago

matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes

matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes

Sunlitmatrix-synapse · matrix-synapseEPSS 0.36%via OSV
CVE-2023-32682Medium· 5.4
3y ago

Synapse has improper checks for deactivated users during login

Synapse has improper checks for deactivated users during login

Sunlitmatrix-synapse · matrix-synapseEPSS 0.75%via OSV
CVE-2019-11842High· 7.5
4y ago

matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG

matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG

Twilightmatrix-sydent · matrix-sydentEPSS 1.6%via OSV
CVE-2018-10657High· 7.5⚠ Exploited0day
4y ago

Matrix Synapse DoS

Matrix Synapse DoS

Abyssalmatrix-synapse · matrix-synapseEPSS 1.5%via OSV
CVE-2018-12291High· 7.5
4y ago

Matrix Synapse Security Filtering Flaw

Matrix Synapse Security Filtering Flaw

Twilightmatrix-synapse · matrix-synapseEPSS 1.6%via OSV
CVE-2018-16515High· 8.8
4y ago

Matrix Synapse Improper Signature Validation

Matrix Synapse Improper Signature Validation

Twilightmatrix-synapse · matrix-synapseEPSS 1.4%via OSV
CVE-2018-12423High· 7.5
4y ago

Matrix Synapse Authorization Error

Matrix Synapse Authorization Error

Twilightmatrix-synapse · matrix-synapseEPSS 1.8%via OSV
CVE-2022-41952Medium· 5.3
4y ago

Uncontrolled Resource Consumption in Matrix Synapse

Uncontrolled Resource Consumption in Matrix Synapse

Sunlitmatrix-synapse · matrix-synapseEPSS 0.87%via OSV
CVE-2021-41281High· 7.5
4y ago

Path traversal in Matrix Synapse

Path traversal in Matrix Synapse

Twilightmatrix-synapse · matrix-synapseEPSS 1.6%via OSV
CVE-2021-39163Low· 3.1
5y ago

Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.

Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.

Sunlitmatrix-synapse · matrix-synapseEPSS 0.90%via OSV
CVE-2021-39164Low· 3.1
5y ago

Improper authorisation of members discloses room membership to non-members

Improper authorisation of members discloses room membership to non-members

Sunlitmatrix-synapse · matrix-synapseEPSS 1.5%via OSV
CVE-2021-29471Low· 3.7
5y ago

Denial of service attack via push rule patterns in matrix-synapse

Denial of service attack via push rule patterns in matrix-synapse

Sunlitmatrix-synapse · matrix-synapseEPSS 1.6%via OSV
CVE-2021-21394Medium· 5.3
5y ago

Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints

Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints

Sunlitmatrix-synapse · matrix-synapseEPSS 1.5%via OSV
CVE-2021-21393Medium· 5.3
5y ago

Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints

Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints

Sunlitmatrix-synapse · matrix-synapseEPSS 1.6%via OSV
CVE-2021-21392Medium· 6.3
5y ago

Open redirect via transitional IPv6 addresses on dual-stack networks

Open redirect via transitional IPv6 addresses on dual-stack networks

Sunlitmatrix-synapse · matrix-synapseEPSS 0.94%via OSV
CVE-2021-21333Medium· 6.1
5y ago

HTML injection in email and account expiry notifications

HTML injection in email and account expiry notifications

Sunlitmatrix-synapse · matrix-synapseEPSS 1.4%via OSV
CVE-2021-21332Medium· 6.9
5y ago

Cross-site scripting (XSS) vulnerability in the password reset endpoint

Cross-site scripting (XSS) vulnerability in the password reset endpoint

Sunlitmatrix-synapse · matrix-synapseEPSS 1.2%via OSV
CVE-2021-21274Medium· 4.3
5y ago

Denial of service attack via .well-known lookups

Denial of service attack via .well-known lookups

Sunlitmatrix-synapse · matrix-synapseEPSS 2.2%via OSV
matrix-synapse vulnerabilities (CVEs) · VulnSea