Matrix

Synapse

40 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 5.78%
  • Published 27.03.2025 00:59:27
  • Last modified 26.08.2025 19:24:45

Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited in the wild and has b...

  • EPSS 0.09%
  • Published 03.12.2024 17:15:12
  • Last modified 26.08.2025 14:59:05

Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option or processing a specially crafted request could trigger the decoding and thumbnail generation of uncommon image formats, potential...

  • EPSS 0.09%
  • Published 03.12.2024 17:15:12
  • Last modified 26.08.2025 15:02:27

Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user's ...

  • EPSS 0.12%
  • Published 03.12.2024 17:15:12
  • Last modified 26.08.2025 15:06:04

Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to ampli...

  • EPSS 0.15%
  • Published 03.12.2024 17:15:10
  • Last modified 26.08.2025 15:09:47

Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media from a remote homeserver to the local media repository. Such content th...

  • EPSS 0.48%
  • Published 03.12.2024 17:15:10
  • Last modified 26.08.2025 15:12:35

Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where an unauthenticated adversary can induce Synapse to download and cache large amounts of remote media. The default rate limit strateg...

  • EPSS 2.3%
  • Published 23.04.2024 18:15:14
  • Last modified 26.08.2025 18:45:47

Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in the V2 state resolution algorithm. This can ...

  • EPSS 0.16%
  • Published 31.10.2023 17:15:23
  • Last modified 13.02.2025 17:17:13

Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver. System administrators are...

  • EPSS 0.25%
  • Published 10.10.2023 18:15:19
  • Last modified 21.11.2024 08:26:24

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service. Homese...

  • EPSS 0.17%
  • Published 27.09.2023 15:19:32
  • Last modified 21.11.2024 08:22:33

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users were able to forge read receipts for any event (if they knew the room ID and event ID). Note that the users were not able to view the events, but s...