matrix-synapse vulnerabilities
CVEs whose affected-version data names the matrix-synapse package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
34 CVEsRSS
CVE-2026-45078Medium· 5.5Synapse CPU starvation (Denial of Service)
Synapse CPU starvation (Denial of Service)
CVE-2026-45076MediumSynapse pagination Denial of Service
Synapse pagination Denial of Service
CVE-2025-61672MediumSynapse's invalid device keys degrade federation functionality
Synapse's invalid device keys degrade federation functionality
CVE-2025-30355High· 7.1Synapse vulnerable to federation denial of service via malformed events
Synapse vulnerable to federation denial of service via malformed events
CVE-2024-53863HighSynapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
CVE-2024-52805HighSynapse allows unsupported content types to lead to memory exhaustion
Synapse allows unsupported content types to lead to memory exhaustion
CVE-2024-52815HighSynapse allows a a malformed invite to break the invitee's `/sync`
Synapse allows a a malformed invite to break the invitee's `/sync`
CVE-2024-53867Medium· 4.3Synapse Matrix has a partial room state leak via Sliding Sync
Synapse Matrix has a partial room state leak via Sliding Sync
CVE-2024-31208Medium· 6.5Synapse V2 state resolution weakness allows Denial of Service (DoS)
Synapse V2 state resolution weakness allows Denial of Service (DoS)
CVE-2023-43796Medium· 5.3Synapse vulnerable to leak of remote user device information
Synapse vulnerable to leak of remote user device information
CVE-2023-45129Medium· 4.9matrix-synapse vulnerable to denial of service due to malicious server ACL events
matrix-synapse vulnerable to denial of service due to malicious server ACL events
CVE-2023-42453Low· 3.1matrix-synapse vulnerable to improper validation of receipts allows forged read receipts
matrix-synapse vulnerable to improper validation of receipts allows forged read receipts
CVE-2023-41335Low· 3.7matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes
matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes
CVE-2023-32682Medium· 5.4Synapse has improper checks for deactivated users during login
Synapse has improper checks for deactivated users during login
CVE-2019-11842High· 7.5matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG
matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG
CVE-2018-10657High· 7.5⚠ Exploited0dayMatrix Synapse DoS
Matrix Synapse DoS
CVE-2018-12291High· 7.5Matrix Synapse Security Filtering Flaw
Matrix Synapse Security Filtering Flaw
CVE-2018-16515High· 8.8Matrix Synapse Improper Signature Validation
Matrix Synapse Improper Signature Validation
CVE-2018-12423High· 7.5Matrix Synapse Authorization Error
Matrix Synapse Authorization Error
CVE-2022-41952Medium· 5.3Uncontrolled Resource Consumption in Matrix Synapse
Uncontrolled Resource Consumption in Matrix Synapse
CVE-2021-41281High· 7.5Path traversal in Matrix Synapse
Path traversal in Matrix Synapse
CVE-2021-39163Low· 3.1Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.
Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.
CVE-2021-39164Low· 3.1Improper authorisation of members discloses room membership to non-members
Improper authorisation of members discloses room membership to non-members
CVE-2021-29471Low· 3.7Denial of service attack via push rule patterns in matrix-synapse
Denial of service attack via push rule patterns in matrix-synapse
CVE-2021-21394Medium· 5.3Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints
Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints
CVE-2021-21393Medium· 5.3Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints
Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints
CVE-2021-21392Medium· 6.3Open redirect via transitional IPv6 addresses on dual-stack networks
Open redirect via transitional IPv6 addresses on dual-stack networks
CVE-2021-21333Medium· 6.1HTML injection in email and account expiry notifications
HTML injection in email and account expiry notifications
CVE-2021-21332Medium· 6.9Cross-site scripting (XSS) vulnerability in the password reset endpoint
Cross-site scripting (XSS) vulnerability in the password reset endpoint
CVE-2021-21274Medium· 4.3Denial of service attack via .well-known lookups
Denial of service attack via .well-known lookups