VendorsMatrixsynapseany version
Vulnerabilities

Matrix Synapse any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

40CVEs
CVE-2019-18835
Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers.
Published 2019-11-07 · Modified
9.8EPSS 0.009
CVE-2024-53863
Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
Published 2024-12-03 · Analyzed
9.1EPSS 0.006
CVE-2018-16515
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
Published 2018-09-18 · Modified
8.8EPSS 0.015
CVE-2024-52815
Synapse allows a a malformed invite to break the invitee's `/sync`
Published 2024-12-03 · Analyzed
8.7EPSS 0.006
CVE-2021-21332
Cross-site scripting (XSS) vulnerability in the password reset endpoint
Published 2021-03-26 · Modified
8.2EPSS 0.012
CVE-2024-52805
Synapse allows unsupported content types to lead to memory exhaustion
Published 2024-12-03 · Analyzed
8.2EPSS 0.007
CVE-2020-26890
Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing remote attackers to execute a denial of service attack against the federation and common Matrix clients. If such a malformed event is accepted into the room's state, the impact is long-lasting and is not fixed by an upgrade to a newer version, requiring the event to be manually redacted instead. Since events are replicated to servers of other room members, the impact is not constrained to the server of the event sender.
Published 2020-11-24 · Modified
7.5EPSS 0.030
CVE-2019-5885
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
Published 2019-03-19 · Modified
7.5EPSS 0.024
CVE-2018-12423
In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.
Published 2018-06-14 · Modified
7.5EPSS 0.018
CVE-2018-12291
The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rules were not applied correctly.
Published 2018-06-13 · Modified
7.5EPSS 0.018
CVE-2019-11842
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.
Published 2019-05-09 · Modified
7.5EPSS 0.018
CVE-2021-41281
Path traversal in Matrix Synapse
Published 2021-11-23 · Modified
7.5EPSS 0.016
CVE-2018-10657
Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018.
Published 2018-05-02 · Modified
7.5EPSS 0.015
CVE-2025-30355
Synapse vulnerable to federation denial of service via malformed events
Published 2025-03-27 · Analyzed
7.5EPSS 0.012
CVE-2022-31152
Synapse vulnerable to denial of service (DoS) due to incorrect application of event authorization rules
Published 2022-09-02 · Modified
7.5EPSS 0.012
CVE-2024-37302
Synapse denial of service through media disk space consumption
Published 2024-12-03 · Analyzed
7.5EPSS 0.006
CVE-2020-26257
Denial of service attack via incorrect parameters to federation APIs
Published 2020-12-09 · Modified
6.5EPSS 0.024
CVE-2021-21274
Denial of service attack via .well-known lookups
Published 2021-02-26 · Modified
6.5EPSS 0.022
CVE-2022-31052
URL previews can crash Synapse media repositories or Synapse monoliths
Published 2022-06-28 · Modified
6.5EPSS 0.017
CVE-2021-21393
Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints
Published 2021-04-12 · Modified
6.5EPSS 0.016
CVE-2021-21394
Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints
Published 2021-04-12 · Modified
6.5EPSS 0.015
CVE-2024-31208
Synapse's V2 state resolution weakness allows DoS from remote room members
Published 2024-04-23 · Analyzed
6.5EPSS 0.015
CVE-2022-39374
Synapse Denial of service due to incorrect application of event authorization rules during state resolution
Published 2023-05-26 · Modified
6.5EPSS 0.009
CVE-2022-41952
Uncontrolled Resource Consumption in Matrix Synapse
Published 2022-11-22 · Modified
6.5EPSS 0.009
CVE-2021-21392
Open redirect via transitional IPv6 addresses on dual-stack networks
Published 2021-04-12 · Modified
6.3EPSS 0.009
CVE-2020-26891
AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsafe interpolation of the session GET parameter. This allows a remote attacker to execute an XSS attack on the domain Synapse is hosted on, by supplying the victim user with a malicious URL to the /_matrix/client/r0/auth/*/fallback/web or /_matrix/client/unstable/auth/*/fallback/web Synapse endpoints.
Published 2020-10-19 · Modified
6.1EPSS 0.019
CVE-2021-21273
Open redirects on some federation and push requests
Published 2021-02-26 · Modified
6.1EPSS 0.018
CVE-2021-21333
HTML injection in email and account expiry notifications
Published 2021-03-26 · Modified
6.1EPSS 0.014
CVE-2023-32682
Improper checks for deactivated users during login in synapse
Published 2023-06-06 · Modified
5.4EPSS 0.008
CVE-2023-32683
URL deny list bypass via oEmbed and image URLs when generating previews in Synapse
Published 2023-06-06 · Modified
5.4EPSS 0.006
CVE-2021-29471
Denial of service in Matrix Synapse
Published 2021-05-11 · Modified
5.3EPSS 0.016
CVE-2023-43796
Synapse vulnerable to leak of remote user device information
Published 2023-10-31 · Modified
5.3EPSS 0.009
CVE-2024-37303
Synapse unauthenticated writes to the media repository allow planting of problematic content
Published 2024-12-03 · Analyzed
5.3EPSS 0.004
CVE-2023-32323
Synapse Outgoing federation to specific hosts can be disabled by sending malicious invites
Published 2023-05-26 · Modified
5.0EPSS 0.010
CVE-2022-39335
Synapse does not apply enough checks to servers requesting auth events of events in a room
Published 2023-05-26 · Modified
5.0EPSS 0.006
CVE-2023-45129
matrix-synapse vulnerable to denial of service due to malicious server ACL events
Published 2023-10-10 · Modified
4.9EPSS 0.012
CVE-2023-42453
Improper validation of receipts allows forged read receipts in matrix synapse
Published 2023-09-26 · Modified
4.3EPSS 0.007
CVE-2023-41335
Temporary storage of plaintext passwords during password changes in matrix synapse
Published 2023-09-26 · Modified
3.7EPSS 0.004
CVE-2021-39164
Improper authorisation of /members discloses room membership to non-members
Published 2021-08-31 · Modified
3.5EPSS 0.015
CVE-2021-39163
Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.
Published 2021-08-31 · Modified
3.5EPSS 0.009