HIGH7.5
PYSEC-2026-846
Matrix Synapse DoS
Quick fix
PYSEC-2026-846 — matrix-synapse: upgrade to the fixed version with the command below.
pip install --upgrade 'matrix-synapse>=0.28.1'Details
Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2<sup>63</sup> - 1 render rooms unusable, related to `federation/federation_base.py` and `handlers/message.py`, as exploited in the wild in April 2018.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/matrix-synapse
Introduced in:
0Fixed in: 0.28.1Fix
pip install --upgrade 'matrix-synapse>=0.28.1'References
- https://nvd.nist.gov/vuln/detail/CVE-2018-10657[ADVISORY]
- https://github.com/matrix-org/synapse/commit/33f469ba19586bbafa0cf2c7d7c35463bdab87eb[WEB]
- https://docs.google.com/document/d/1I3fi2S-XnpO45qrpCsowZv8P8dHcNZ4fsBsbOW7KABI/edit#heading=h.fj95ykuss7s1[WEB]
- https://github.com/matrix-org/synapse[PACKAGE]
- https://matrix.org/blog/2018/05/01/security-update-synapse-0-28-1[WEB]
- https://pypi.org/project/matrix-synapse[PACKAGE]
- https://github.com/advisories/GHSA-vmcc-4p4x-x7wg[ADVISORY]