URL previews of unusual or maliciously-crafted pages can crash Synapse media repositories or Synapse monoliths
Modified: 9/30/2024
package
pkg:pypi/matrix-synapse
URL previews of unusual or maliciously-crafted pages can crash Synapse media repositories or Synapse monoliths
Modified: 9/30/2024
Cross-site scripting (XSS) vulnerability in the password reset endpoint
Modified: 7/8/2026
Synapse has improper checks for deactivated users during login
Modified: 9/10/2026
Denial of service attack via .well-known lookups
Modified: 9/10/2026
Synapse V2 state resolution weakness allows Denial of Service (DoS)
Modified: 9/10/2026
Path traversal in Matrix Synapse
Modified: 7/8/2026
Improper authorisation of members discloses room membership to non-members
Modified: 7/8/2026
Cross-site scripting (XSS) vulnerability in the fallback authentication endpoint
Modified: 7/8/2026
Synapse does not apply enough checks to servers requesting auth events of events in a room
Modified: 9/24/2024
Uncontrolled Resource Consumption in Matrix Synapse
Modified: 7/6/2026
matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes
Modified: 9/10/2026
Synapse denial of service through media disk space consumption
Modified: 6/6/2026
Denial of service attack due to invalid JSON
Modified: 7/8/2026
Synapse Matrix has a partial room state leak via Sliding Sync
Modified: 7/7/2026
matrix-synapse vulnerable to denial of service due to malicious server ACL events
Modified: 9/10/2026
Open redirect via transitional IPv6 addresses on dual-stack networks
Modified: 7/8/2026
Synapse pagination Denial of Service
Modified: 9/10/2026
matrix-synapse vulnerable to improper validation of receipts allows forged read receipts
Modified: 9/10/2026
Denial of service (via resource exhaustion) due to improper input validation in third-party identifier endpoint
Modified: 12/2/2024
Synapse CPU starvation (Denial of Service)
Modified: 9/10/2026
Synapse has URL deny list bypass via oEmbed and image URLs when generating previews
Modified: 9/30/2024
HTML injection in email and account expiry notifications
Modified: 7/8/2026
Matrix Synapse Authorization Error
Modified: 7/7/2026
Improper Verification of Cryptographic Signature in matrix-synapse
Modified: 2/15/2025
Synapse allows a a malformed invite to break the invitee's `/sync`
Modified: 7/7/2026
Synapse Outgoing federation to specific hosts can be disabled by sending malicious invites
Modified: 2/13/2025
Synapse's invalid device keys degrade federation functionality
Modified: 7/7/2026
Matrix Synapse Improper Signature Validation
Modified: 7/7/2026
Synapse's unauthenticated writes to the media repository allow planting of problematic content
Modified: 6/6/2026
matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG
Modified: 7/13/2026
Denial of service attack via incorrect parameters in Matrix Synapse
Modified: 9/10/2026
Denial of service due to incorrect application of event authorization rules
Modified: 9/30/2024
Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.
Modified: 7/8/2026
Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints
Modified: 7/8/2026
Matrix Synapse Predictable Secret Key
Modified: 9/24/2024
Synapse vulnerable to leak of remote user device information
Modified: 9/10/2026
Synapse Denial of service due to incorrect application of event authorization rules during state resolution
Modified: 9/30/2024
Synapse allows unsupported content types to lead to memory exhaustion
Modified: 7/7/2026
Synapse vulnerable to federation denial of service via malformed events
Modified: 7/7/2026
Matrix Synapse Security Filtering Flaw
Modified: 7/6/2026
Open redirects on some federation and push requests
Modified: 7/8/2026
Matrix Synapse DoS
Modified: 7/7/2026
Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
Modified: 7/7/2026
Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints
Modified: 7/8/2026
Denial of service attack via push rule patterns in matrix-synapse
Modified: 7/8/2026
Modified: 7/13/2026
Modified: 11/8/2023
Modified: 6/10/2026
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 2/26/2026
Modified: 2/26/2026
Modified: 2/26/2026
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 11/8/2023
Modified: 5/20/2026
Modified: 5/20/2026
Modified: 4/23/2024
Synapse Matrix has a partial room state leak via Sliding Sync
Modified: 7/7/2026
Synapse allows a a malformed invite to break the invitee's `/sync`
Modified: 7/7/2026
Synapse's invalid device keys degrade federation functionality
Modified: 7/7/2026
Synapse allows unsupported content types to lead to memory exhaustion
Modified: 7/7/2026
Synapse vulnerable to federation denial of service via malformed events
Modified: 7/7/2026
Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
Modified: 7/7/2026
Modified: 6/3/2026
Modified: 6/5/2026
Uncontrolled Resource Consumption in Matrix Synapse
Modified: 7/6/2026
Matrix Synapse Security Filtering Flaw
Modified: 7/6/2026
Matrix Synapse Authorization Error
Modified: 7/7/2026
Matrix Synapse Improper Signature Validation
Modified: 7/7/2026
Matrix Synapse DoS
Modified: 7/7/2026