Synapse
Element-HQ · 11 CVEs
Synapse CPU starvation (Denial of Service)
May 28, 2026
Synapse pagination denial of service
May 28, 2026
Synapse: Invalid device keys degrade federation functionality
Oct 8, 2025
Synapse vulnerable to federation denial of service via malformed events
Mar 27, 2025
Synapse unauthenticated writes to the media repository allow planting of problematic content
Dec 3, 2024
Synapse denial of service through media disk space consumption
Dec 3, 2024
Synapse allows unsupported content types to lead to memory exhaustion
Dec 3, 2024
Synapse allows a a malformed invite to break the invitee's `/sync`
Dec 3, 2024
Synapse Matrix has a partial room state leak via Sliding Sync
Dec 3, 2024
Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
Dec 3, 2024
Synapse's V2 state resolution weakness allows DoS from remote room members
Apr 23, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-45078 | Synapse CPU starvation (Denial of Service) | HIGH | 0.13% | May 28, 2026 |
| CVE-2026-45076 | Synapse pagination denial of service | MEDIUM | 0.39% | May 28, 2026 |
| CVE-2025-61672 | Synapse: Invalid device keys degrade federation functionality | MEDIUM | 0.47% | Oct 8, 2025 |
| CVE-2025-30355 | Synapse vulnerable to federation denial of service via malformed events | HIGH | 1.20% | Mar 27, 2025 |
| CVE-2024-37303 | Synapse unauthenticated writes to the media repository allow planting of problematic content | MEDIUM | 0.43% | Dec 3, 2024 |
| CVE-2024-37302 | Synapse denial of service through media disk space consumption | HIGH | 0.60% | Dec 3, 2024 |
| CVE-2024-52805 | Synapse allows unsupported content types to lead to memory exhaustion | HIGH | 0.74% | Dec 3, 2024 |
| CVE-2024-52815 | Synapse allows a a malformed invite to break the invitee's `/sync` | HIGH | 0.57% | Dec 3, 2024 |
| CVE-2024-53867 | Synapse Matrix has a partial room state leak via Sliding Sync | MEDIUM | 0.44% | Dec 3, 2024 |
| CVE-2024-53863 | Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders | HIGH | 0.61% | Dec 3, 2024 |
| CVE-2024-31208 | Synapse's V2 state resolution weakness allows DoS from remote room members | MEDIUM | 1.46% | Apr 23, 2024 |
Showing 1 to 11 of 11 CVEs