VDB
Sign up
HIGH8.8

PYSEC-2026-845

Matrix Synapse Improper Signature Validation

Quick fix

PYSEC-2026-845 — matrix-synapse: upgrade to the fixed version with the command below.

pip install --upgrade 'matrix-synapse>=0.33.2.1'

Details

Matrix Synapse before 0.33.3.1 and 0.33.2.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/matrix-synapse
Introduced in: 0Fixed in: 0.33.2.1
Fixpip install --upgrade 'matrix-synapse>=0.33.2.1'

References