CVE-2024-31208
published 2024-04-23CVE-2024-31208: Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
1.46%
70.7th percentile
Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in the V2 state resolution algorithm. This can induce high CPU consumption and accumulate excessive data in the database of such instances, resulting in a denial of service. Servers in private federations, or those that do not federate, are not affected. Server administrators should upgrade to 1.105.1 or later. Some workarounds are available. One can ban the malicious users or ACL block servers from the rooms and/or leave the room and purge the room using the admin API.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | matrix-synapse | < matrix-synapse 1.103.0-2 (forky) | matrix-synapse 1.103.0-2 (forky) |
| element-hq | synapse | < 1.105.1 | 1.105.1 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| matrix | synapse | < 1.105.1 | 1.105.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Synapse vulnerabilities
vendor_ubuntu·2025-04-22·CVSS 5.0
CVE-2023-41335 [MEDIUM] Synapse vulnerabilities
Title: Synapse vulnerabilities
Summary: Several security issues were fixed in Synapse.
It was discovered that Synapse network policies could be bypassed via
specially crafted URLs. An attacker could possibly use this issue to
bypass authentication mechanisms. (CVE-2023-32683)
It was discovered that Synapse exposed cached device information. An
attacker could possibly use this issue to gain access to sensitive
information. (CVE-2023-43796)
It was discovered that Synapse could be tricked into rejecting state
changes in rooms. An attacker could possibly use this issue to cause
Synapse to stop functioning properly, resulting in a denial of service.
This issue was only fixed in Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-39374)
It was discovered that Synapse stored user credentials in
Debian
CVE-2024-31208: matrix-synapse - Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious...
vendor_debian·2024·CVSS 6.5
CVE-2024-31208 [MEDIUM] CVE-2024-31208: matrix-synapse - Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious...
Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in the V2 state resolution algorithm. This can induce high CPU consumption and accumulate excessive data in the database of such instances, resulting in a denial of service. Servers in private federations, or those that do not federate, are not affected. Server administrators should upgrade to 1.105.1 or later. Some workarounds are available. One can ban the malicious users or ACL block servers from the rooms and/or leave the room and purge the room using the admin API.
Scope: local
forky: resolved (fixed in 1.103.0-2)
sid: resolved (fixed in 1.103.0-2)
OSV
matrix-synapse vulnerabilities
osv·2025-04-22·CVSS 5.0
CVE-2023-32683 [MEDIUM] matrix-synapse vulnerabilities
matrix-synapse vulnerabilities
It was discovered that Synapse network policies could be bypassed via
specially crafted URLs. An attacker could possibly use this issue to
bypass authentication mechanisms. (CVE-2023-32683)
It was discovered that Synapse exposed cached device information. An
attacker could possibly use this issue to gain access to sensitive
information. (CVE-2023-43796)
It was discovered that Synapse could be tricked into rejecting state
changes in rooms. An attacker could possibly use this issue to cause
Synapse to stop functioning properly, resulting in a denial of service.
This issue was only fixed in Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-39374)
It was discovered that Synapse stored user credentials in a server's
database temporarily. An attacker could possi
OSV
CVE-2024-31208: Synapse is an open-source Matrix homeserver
osv·2024-04-23·CVSS 6.5
CVE-2024-31208 [MEDIUM] CVE-2024-31208: Synapse is an open-source Matrix homeserver
Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in the V2 state resolution algorithm. This can induce high CPU consumption and accumulate excessive data in the database of such instances, resulting in a denial of service. Servers in private federations, or those that do not federate, are not affected. Server administrators should upgrade to 1.105.1 or later. Some workarounds are available. One can ban the malicious users or ACL block servers from the rooms and/or leave the room and purge the room using the admin API.
GHSA
Synapse V2 state resolution weakness allows Denial of Service (DoS)
ghsa·2024-04-23
CVE-2024-31208 [MEDIUM] CWE-770 Synapse V2 state resolution weakness allows Denial of Service (DoS)
Synapse V2 state resolution weakness allows Denial of Service (DoS)
### Impact
A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in how the auth chain cover index is calculated. This can induce high CPU consumption and accumulate excessive data in the database of such instances, resulting in a denial of service.
Servers in private federations, or those that do not federate, are not affected.
### Patches
Server administrators should upgrade to 1.105.1 or later.
### Workarounds
One can:
- ban the malicious users or ACL block servers from the rooms; and/or
- leave the room and purge the room using the admin API
### For more information
If you have any questions or comments abou
OSV
Synapse V2 state resolution weakness allows Denial of Service (DoS)
osv·2024-04-23
CVE-2024-31208 [MEDIUM] Synapse V2 state resolution weakness allows Denial of Service (DoS)
Synapse V2 state resolution weakness allows Denial of Service (DoS)
### Impact
A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in how the auth chain cover index is calculated. This can induce high CPU consumption and accumulate excessive data in the database of such instances, resulting in a denial of service.
Servers in private federations, or those that do not federate, are not affected.
### Patches
Server administrators should upgrade to 1.105.1 or later.
### Workarounds
One can:
- ban the malicious users or ACL block servers from the rooms; and/or
- leave the room and purge the room using the admin API
### For more information
If you have any questions or comments abou
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/element-hq/synapse/commit/55b0aa847a61774b6a3acdc4b177a20dc019f01ahttps://github.com/element-hq/synapse/releases/tag/v1.105.1https://github.com/element-hq/synapse/security/advisories/GHSA-3h7q-rfh9-xm4vhttps://lists.fedoraproject.org/archives/list/[email protected]/message/R6FCCO4ODTZ3FDS7TMW76PKOSEL2TQVB/https://lists.fedoraproject.org/archives/list/[email protected]/message/RR53FNHV446CB37TP45GZ6F6HZLZCK3K/https://lists.fedoraproject.org/archives/list/[email protected]/message/VSF4NJJSTSQRJQ47PLYYSCFYKJBP7DET/https://github.com/element-hq/synapse/commit/55b0aa847a61774b6a3acdc4b177a20dc019f01ahttps://github.com/element-hq/synapse/releases/tag/v1.105.1https://github.com/element-hq/synapse/security/advisories/GHSA-3h7q-rfh9-xm4vhttps://lists.fedoraproject.org/archives/list/[email protected]/message/R6FCCO4ODTZ3FDS7TMW76PKOSEL2TQVB/https://lists.fedoraproject.org/archives/list/[email protected]/message/RR53FNHV446CB37TP45GZ6F6HZLZCK3K/https://lists.fedoraproject.org/archives/list/[email protected]/message/VSF4NJJSTSQRJQ47PLYYSCFYKJBP7DET/
2024-04-23
Published