VulnSea

matrix-synapse has 33 CVEs on record between 2020 and 2026. The median CVSS is 5.5 (medium). 3% have been exploited in the wild, in line with the corpus average.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
3% vs 1% corpus
Median CVSS
5.5
Publish → KEV
Last 90 days
0 prev 2

Products

  • matrix-synapse 33
33
Total CVEs
0
Critical
0
CISA KEV
1
Exploited

matrix-synapse vulnerabilities

CVEs affecting matrix-synapse, newest first. Open any entry for full detail, references, and exploit status.

33 CVEsRSS

CVE-2026-45078Medium· 5.5
4mo ago

Synapse CPU starvation (Denial of Service)

Synapse CPU starvation (Denial of Service)

Sunlitmatrix-synapse · matrix-synapseEPSS 0.13%via OSV
CVE-2026-45076Medium
4mo ago

Synapse pagination Denial of Service

Synapse pagination Denial of Service

Sunlitmatrix-synapse · matrix-synapseEPSS 0.37%via OSV
CVE-2025-61672Medium
11mo ago

Synapse's invalid device keys degrade federation functionality

Synapse's invalid device keys degrade federation functionality

Sunlitmatrix-synapse · matrix-synapseEPSS 0.47%via OSV
CVE-2025-30355High· 7.1
1y ago

Synapse vulnerable to federation denial of service via malformed events

Synapse vulnerable to federation denial of service via malformed events

Twilightmatrix-synapse · matrix-synapseEPSS 1.2%via OSV
CVE-2024-53863High
1y ago

Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders

Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders

Twilightmatrix-synapse · matrix-synapseEPSS 0.61%via OSV
CVE-2024-52805High
1y ago

Synapse allows unsupported content types to lead to memory exhaustion

Synapse allows unsupported content types to lead to memory exhaustion

Twilightmatrix-synapse · matrix-synapseEPSS 0.74%via OSV
CVE-2024-52815High
1y ago

Synapse allows a a malformed invite to break the invitee's `/sync`

Synapse allows a a malformed invite to break the invitee's `/sync`

Twilightmatrix-synapse · matrix-synapseEPSS 0.57%via OSV
CVE-2024-53867Medium· 4.3
1y ago

Synapse Matrix has a partial room state leak via Sliding Sync

Synapse Matrix has a partial room state leak via Sliding Sync

Sunlitmatrix-synapse · matrix-synapseEPSS 0.44%via OSV
CVE-2024-31208Medium· 6.5
2y ago

Synapse V2 state resolution weakness allows Denial of Service (DoS)

Synapse V2 state resolution weakness allows Denial of Service (DoS)

Sunlitmatrix-synapse · matrix-synapseEPSS 1.5%via OSV
CVE-2023-43796Medium· 5.3
2y ago

Synapse vulnerable to leak of remote user device information

Synapse vulnerable to leak of remote user device information

Sunlitmatrix-synapse · matrix-synapseEPSS 0.90%via OSV
CVE-2023-45129Medium· 4.9
2y ago

matrix-synapse vulnerable to denial of service due to malicious server ACL events

matrix-synapse vulnerable to denial of service due to malicious server ACL events

Sunlitmatrix-synapse · matrix-synapseEPSS 1.2%via OSV
CVE-2023-42453Low· 3.1
2y ago

matrix-synapse vulnerable to improper validation of receipts allows forged read receipts

matrix-synapse vulnerable to improper validation of receipts allows forged read receipts

Sunlitmatrix-synapse · matrix-synapseEPSS 0.65%via OSV
CVE-2023-41335Low· 3.7
2y ago

matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes

matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes

Sunlitmatrix-synapse · matrix-synapseEPSS 0.36%via OSV
CVE-2023-32682Medium· 5.4
3y ago

Synapse has improper checks for deactivated users during login

Synapse has improper checks for deactivated users during login

Sunlitmatrix-synapse · matrix-synapseEPSS 0.75%via OSV
CVE-2018-10657High· 7.5⚠ Exploited0day
4y ago

Matrix Synapse DoS

Matrix Synapse DoS

Abyssalmatrix-synapse · matrix-synapseEPSS 1.5%via OSV
CVE-2018-12291High· 7.5
4y ago

Matrix Synapse Security Filtering Flaw

Matrix Synapse Security Filtering Flaw

Twilightmatrix-synapse · matrix-synapseEPSS 1.6%via OSV
CVE-2018-16515High· 8.8
4y ago

Matrix Synapse Improper Signature Validation

Matrix Synapse Improper Signature Validation

Twilightmatrix-synapse · matrix-synapseEPSS 1.4%via OSV
CVE-2018-12423High· 7.5
4y ago

Matrix Synapse Authorization Error

Matrix Synapse Authorization Error

Twilightmatrix-synapse · matrix-synapseEPSS 1.8%via OSV
CVE-2022-41952Medium· 5.3
4y ago

Uncontrolled Resource Consumption in Matrix Synapse

Uncontrolled Resource Consumption in Matrix Synapse

Sunlitmatrix-synapse · matrix-synapseEPSS 0.87%via OSV
CVE-2021-41281High· 7.5
4y ago

Path traversal in Matrix Synapse

Path traversal in Matrix Synapse

Twilightmatrix-synapse · matrix-synapseEPSS 1.6%via OSV
CVE-2021-39163Low· 3.1
5y ago

Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.

Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.

Sunlitmatrix-synapse · matrix-synapseEPSS 0.90%via OSV
CVE-2021-39164Low· 3.1
5y ago

Improper authorisation of members discloses room membership to non-members

Improper authorisation of members discloses room membership to non-members

Sunlitmatrix-synapse · matrix-synapseEPSS 1.5%via OSV
CVE-2021-29471Low· 3.7
5y ago

Denial of service attack via push rule patterns in matrix-synapse

Denial of service attack via push rule patterns in matrix-synapse

Sunlitmatrix-synapse · matrix-synapseEPSS 1.6%via OSV
CVE-2021-21394Medium· 5.3
5y ago

Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints

Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints

Sunlitmatrix-synapse · matrix-synapseEPSS 1.5%via OSV
CVE-2021-21393Medium· 5.3
5y ago

Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints

Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints

Sunlitmatrix-synapse · matrix-synapseEPSS 1.6%via OSV
CVE-2021-21392Medium· 6.3
5y ago

Open redirect via transitional IPv6 addresses on dual-stack networks

Open redirect via transitional IPv6 addresses on dual-stack networks

Sunlitmatrix-synapse · matrix-synapseEPSS 0.94%via OSV
CVE-2021-21333Medium· 6.1
5y ago

HTML injection in email and account expiry notifications

HTML injection in email and account expiry notifications

Sunlitmatrix-synapse · matrix-synapseEPSS 1.4%via OSV
CVE-2021-21332Medium· 6.9
5y ago

Cross-site scripting (XSS) vulnerability in the password reset endpoint

Cross-site scripting (XSS) vulnerability in the password reset endpoint

Sunlitmatrix-synapse · matrix-synapseEPSS 1.2%via OSV
CVE-2021-21274Medium· 4.3
5y ago

Denial of service attack via .well-known lookups

Denial of service attack via .well-known lookups

Sunlitmatrix-synapse · matrix-synapseEPSS 2.2%via OSV
CVE-2021-21273Low· 3.1
5y ago

Open redirects on some federation and push requests

Open redirects on some federation and push requests

Sunlitmatrix-synapse · matrix-synapseEPSS 1.8%via OSV
matrix-synapse vulnerabilities (CVEs) · VulnSea