Matrix

Synapse

40 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 5.78%
  • Veröffentlicht 27.03.2025 00:59:27
  • Zuletzt bearbeitet 26.08.2025 19:24:45

Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited in the wild and has b...

  • EPSS 0.09%
  • Veröffentlicht 03.12.2024 17:15:12
  • Zuletzt bearbeitet 26.08.2025 14:59:05

Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option or processing a specially crafted request could trigger the decoding and thumbnail generation of uncommon image formats, potential...

  • EPSS 0.09%
  • Veröffentlicht 03.12.2024 17:15:12
  • Zuletzt bearbeitet 26.08.2025 15:02:27

Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user's ...

  • EPSS 0.12%
  • Veröffentlicht 03.12.2024 17:15:12
  • Zuletzt bearbeitet 26.08.2025 15:06:04

Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to ampli...

  • EPSS 0.15%
  • Veröffentlicht 03.12.2024 17:15:10
  • Zuletzt bearbeitet 26.08.2025 15:09:47

Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media from a remote homeserver to the local media repository. Such content th...

  • EPSS 0.48%
  • Veröffentlicht 03.12.2024 17:15:10
  • Zuletzt bearbeitet 26.08.2025 15:12:35

Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where an unauthenticated adversary can induce Synapse to download and cache large amounts of remote media. The default rate limit strateg...

  • EPSS 2.3%
  • Veröffentlicht 23.04.2024 18:15:14
  • Zuletzt bearbeitet 26.08.2025 18:45:47

Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in the V2 state resolution algorithm. This can ...

  • EPSS 0.16%
  • Veröffentlicht 31.10.2023 17:15:23
  • Zuletzt bearbeitet 13.02.2025 17:17:13

Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver. System administrators are...

  • EPSS 0.25%
  • Veröffentlicht 10.10.2023 18:15:19
  • Zuletzt bearbeitet 21.11.2024 08:26:24

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service. Homese...

  • EPSS 0.17%
  • Veröffentlicht 27.09.2023 15:19:32
  • Zuletzt bearbeitet 21.11.2024 08:22:33

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users were able to forge read receipts for any event (if they knew the room ID and event ID). Note that the users were not able to view the events, but s...