matrix-synapse vulnerabilities
CVEs whose affected-version data names the matrix-synapse package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
34 CVEsRSS
CVE-2021-21273Low· 3.1Open redirects on some federation and push requests
Open redirects on some federation and push requests
▾ Sunlitmatrix-synapse · matrix-synapseEPSS 1.8%via OSV
CVE-2020-26257Medium· 6.5Denial of service attack via incorrect parameters in Matrix Synapse
Denial of service attack via incorrect parameters in Matrix Synapse
▾ Sunlitmatrix-synapse · matrix-synapseEPSS 2.4%via OSV
CVE-2020-26890High· 7.5Denial of service attack due to invalid JSON
Denial of service attack due to invalid JSON
▾ Twilightmatrix-synapse · matrix-synapseEPSS 3.0%via OSV
CVE-2020-26891Medium· 6.1Cross-site scripting (XSS) vulnerability in the fallback authentication endpoint
Cross-site scripting (XSS) vulnerability in the fallback authentication endpoint
▾ Sunlitmatrix-synapse · matrix-synapseEPSS 1.9%via OSV