Matrix / Synapse
40 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-30355 | Synapse vulnerable to federation denial of service via malformed events | HIGH | 7.5 | Mar 27, 2025 |
| CVE-2024-37303 | Synapse unauthenticated writes to the media repository allow planting of problematic content | MEDIUM | 6.9 | Dec 3, 2024 |
| CVE-2024-37302 | Synapse denial of service through media disk space consumption | HIGH | 8.7 | Dec 3, 2024 |
| CVE-2024-52805 | Synapse allows unsupported content types to lead to memory exhaustion | HIGH | 8.2 | Dec 3, 2024 |
| CVE-2024-52815 | Synapse allows a a malformed invite to break the invitee's `/sync` | HIGH | 8.7 | Dec 3, 2024 |
| CVE-2024-53863 | Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders | HIGH | 8.2 | Dec 3, 2024 |
| CVE-2024-31208 | Synapse's V2 state resolution weakness allows DoS from remote room members | MEDIUM | 6.5 | Apr 23, 2024 |
| CVE-2023-43796 | Synapse vulnerable to leak of remote user device information | MEDIUM | 5.3 | Oct 31, 2023 |
| CVE-2023-45129 | matrix-synapse vulnerable to denial of service due to malicious server ACL events | MEDIUM | 6.9 | Oct 10, 2023 |
| CVE-2023-41335 | Temporary storage of plaintext passwords during password changes in matrix synapse | LOW | 2.0 | Sep 26, 2023 |
| CVE-2023-42453 | Improper validation of receipts allows forged read receipts in matrix synapse | MEDIUM | 6.3 | Sep 26, 2023 |
| CVE-2023-32683 | URL deny list bypass via oEmbed and image URLs when generating previews in Synapse | MEDIUM | 5.1 | Jun 6, 2023 |
| CVE-2023-32682 | Improper checks for deactivated users during login in synapse | MEDIUM | 5.3 | Jun 6, 2023 |
| CVE-2022-39374 | Synapse Denial of service due to incorrect application of event authorization rules during state resolution | HIGH | 7.1 | May 26, 2023 |
| CVE-2022-39335 | Synapse does not apply enough checks to servers requesting auth events of events in a room | HIGH | 7.7 | May 26, 2023 |
| CVE-2023-32323 | Synapse Outgoing federation to specific hosts can be disabled by sending malicious invites | MEDIUM | 5.3 | May 26, 2023 |
| CVE-2022-41952 | Uncontrolled Resource Consumption in Matrix Synapse | MEDIUM | 6.5 | Nov 22, 2022 |
| CVE-2022-31152 | Synapse vulnerable to denial of service (DoS) due to incorrect application of event authorization rules | HIGH | 8.7 | Sep 2, 2022 |
| CVE-2022-31052 | URL previews can crash Synapse media repositories or Synapse monoliths | HIGH | 7.1 | Jun 28, 2022 |
| CVE-2021-41281 | Path traversal in Matrix Synapse | HIGH | 8.7 | Nov 23, 2021 |
| CVE-2021-39164 | Improper authorisation of /members discloses room membership to non-members | LOW | 3.1 | Aug 31, 2021 |
| CVE-2021-39163 | Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner. | LOW | 2.3 | Aug 31, 2021 |
| CVE-2021-29471 | Denial of service in Matrix Synapse | MEDIUM | 6.3 | May 11, 2021 |
| CVE-2021-21392 | Open redirect via transitional IPv6 addresses on dual-stack networks | HIGH | 7.1 | Apr 12, 2021 |
| CVE-2021-21393 | Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints | MEDIUM | 6.0 | Apr 12, 2021 |
Showing 1 to 25 of 40 CVEs