Matrix-synapse

Latest version: v1.121.1

Vulnerabilities (41)

CVE/PVE Vulnerability ID Advisory Affected versions Severity Severity Score
CVE-2023-43796 65800

Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 …

  • <1.95.1
MEDIUM 5.3
CVE-2023-45129 65801

Synapse is an open-source Matrix homeserver written and maintained by…

  • <1.94.0
MEDIUM 4.9
CVE-2023-32683 58943

Matrix-synapse 1.85.0 includes a security fix: URL deny list bypass v…

  • <1.85.0
MEDIUM 5.4
CVE-2023-32682 58942

Matrix-synapse 1.85.0 includes a security fix: Improper checks for de…

  • <1.85.0
MEDIUM 5.4
CVE-2023-32323 64197

Synapse is an open-source Matrix homeserver written and maintained by…

  • <1.74.0
MEDIUM 4.3
CVE-2022-39335 62766

Synapse is an open-source Matrix homeserver written and maintained by…

  • <1.69.0
MEDIUM 5.0
CVE-2023-41335 65798

Synapse is an open-source Matrix homeserver written and maintained by…

  • >=1.66.0,<1.93.0
LOW 3.7
CVE-2022-39374 62713

Synapse is an open-source Matrix homeserver written and maintained by…

  • >=1.62.0,<1.68.0
MEDIUM 6.5
CVE-2021-41281 42808

Matrix-synapse 1.47.1 includes a fix for CVE-2021-41281: Prior to ver…

  • <1.47.1
HIGH 7.5
CVE-2023-42453 65799

Synapse is an open-source Matrix homeserver written and maintained by…

  • >=1.34.0,<1.93.0
MEDIUM 4.3
CVE-2021-29471 40438

Matrix-synapse 1.33.2 includes a fix for CVE-2021-29471: Synapse is a…

  • <1.33.2
MEDIUM 5.3
PVE-2023-55173 55173

Matrix-synapse 1.33.0 includes a security fix: Denial of service (via…

  • <1.33.0
- -
CVE-2021-21392 42303

Synapse 1.28.0 includes a fix for CVE-2021-21392: In Synapse before v…

  • <1.28.0
MEDIUM 6.3
CVE-2021-21333 40107

Matrix-synapse 1.27.0 includes a fix for CVE-2021-21333: In Synapse b…

  • <1.27.0
MEDIUM 6.1
CVE-2021-21332 40106

Matrix-synapse 1.27.0 includes a fix for CVE-2021-21332: In Synapse b…

  • <1.27.0
HIGH 8.2
CVE-2021-21273 39661

Matrix-synapse 1.25.0 includes a fix for CVE-2021-21273: Open redirec…

  • <1.25.0
MEDIUM 6.1
CVE-2024-53867 74421

Matrix-synapse can leak partial room state changes to users no longer…

  • <1.120.1
- -
CVE-2024-53863 74422

Affected versions of Synapse are vulnerable to sensitive system infor…

  • <1.120.1
- -
CVE-2024-52815 74423

Affected versions of Synapse are vulnerable to improper input validat…

  • <1.120.1
- -
CVE-2024-52805 74424

Affected versions of Synapse are vulnerable to allocation of resource…

  • <1.120.1
- -
CVE-2024-37303 74425

Affected versions of Synapse are vulnerable to Missing Authentication…

  • <1.106
- -
CVE-2024-37302 74426

Affected versions of Synapse are vulnerable to Allocation of Resource…

  • <1.106
- -
CVE-2024-31208 71894

Synapse is an open-source Matrix homeserver. A remote Matrix user wit…

  • <1.105.1
- -
CVE-2021-21274 39662

Matrix-synapse 1.25.0 includes a fix for CVE-2021-21274: Denial of se…

  • >0.99.0,<1.25.0
MEDIUM 6.5
CVE-2018-16515 67948

Matrix Synapse before 0.33.3.1 allows remote attackers to spoof event…

  • <0.33.3.1
HIGH 8.8
CVE-2018-12423 67947

In Synapse before 0.31.2, unauthorised users can hijack rooms when th…

  • <0.31.2
HIGH 7.5
CVE-2018-12291 67946

The on_get_missing_events function in handlers/federation.py in Matri…

  • <0.31.1
HIGH 7.5
CVE-2018-10657 65844

Matrix Synapse before 0.28.1 is prone to a denial of service flaw whe…

  • <0.28.1
HIGH 7.5
CVE-2021-21393 42304

Synapse 1.28.0 includes a fix for CVE-2021-21393. Missing input valid…

  • >0.24.0,<1.28.0
MEDIUM 6.5
CVE-2021-21394 42305

Synapse 1.28.0 includes a fix for CVE-2021-21394: Synapse before vers…

  • >=0.17.0,<1.28.0
MEDIUM 6.5
CVE-2022-31152 54524

Synapse is an open-source Matrix homeserver written and maintained by…

  • >=0,<1.62.0
HIGH 7.5
CVE-2022-31052 54430

Synapse is an open source home server implementation for the Matrix c…

  • >=0,<1.61.1
MEDIUM 6.5
CVE-2022-41952 54590

Synapse before 1.52.0 with URL preview functionality enabled will att…

  • >=0,<1.53.0
MEDIUM 5.3
CVE-2019-18835 54217

Matrix Synapse before 1.5.0 mishandles signature checking on some fed…

  • >=0,<1.5.0
CRITICAL 9.8
CVE-2021-39164 54315

Matrix is an ecosystem for open federated Instant Messaging and Voice…

  • >=0,<1.41.1
LOW 3.1
CVE-2021-39163 54333

Matrix is an ecosystem for open federated Instant Messaging and Voice…

  • >=0,<1.41.1
LOW 3.1
CVE-2020-26257 54252

Matrix is an ecosystem for open federated Instant Messaging and VoIP.…

  • >=0,<1.23.1
MEDIUM 6.5
CVE-2020-26891 54234

AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS …

  • >=0,<1.21.0
MEDIUM 6.1
CVE-2020-26890 54308

Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, In…

  • >=0,<1.20.0
HIGH 7.5
CVE-2019-11842 54137

An issue was discovered in Matrix Sydent before 1.0.3 and Synapse bef…

  • >=0,<0.99.3.1
HIGH 7.5
CVE-2019-5885 54170

Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authenti…

  • >=0,<0.34.0.1
HIGH 7.5