HIGH7.5
PYSEC-2026-844
Matrix Synapse Authorization Error
Quick fix
PYSEC-2026-844 — matrix-synapse: upgrade to the fixed version with the command below.
pip install --upgrade 'matrix-synapse>=0.31.2'Details
In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no `m.room.power_levels` event in force.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/matrix-synapse
Introduced in:
0Fixed in: 0.31.2Fix
pip install --upgrade 'matrix-synapse>=0.31.2'References
- https://nvd.nist.gov/vuln/detail/CVE-2018-12423[ADVISORY]
- https://github.com/matrix-org/matrix-doc/issues/1304[WEB]
- https://bugs.debian.org/901549[WEB]
- https://github.com/matrix-org/synapse[PACKAGE]
- https://matrix.org/blog/2018/06/14/security-update-synapse-0-31-2[WEB]
- https://pypi.org/project/matrix-synapse[PACKAGE]
- https://github.com/advisories/GHSA-ch5v-fhg8-7gv9[ADVISORY]