Debian Matrix-Synapse vulnerabilities
44 known vulnerabilities affecting debian/matrix-synapse.
Total CVEs
44
CISA KEV
0
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL1HIGH14MEDIUM22LOW7
Vulnerabilities
Page 1 of 3
CVE-2025-30355P2HIGHCVSS 7.1Exploitedfixed in matrix-synapse 1.121.0-6 (forky)2025
CVE-2025-30355 [HIGH] CVE-2025-30355: matrix-synapse - Synapse is an open source Matrix homeserver implementation. A malicious server c...
Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited in the wild and has been fixed in Synapse v1.127.1. No known workarounds are available.
Scope: local
forky: resolved (fixed in 1.121
debian
CVE-2018-10657P2HIGHCVSS 7.5Exploitedfixed in matrix-synapse 0.28.1+dfsg-1 (forky)2018
CVE-2018-10657 [HIGH] CVE-2018-10657: matrix-synapse - Matrix Synapse before 0.28.1 is prone to a denial of service flaw where maliciou...
Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018.
Scope: local
forky: resolved (fixed in 0.28.1+dfsg-1)
sid: resolved (fixed in 0.28.1+dfsg-1)
debian
CVE-2024-53863P3HIGHCVSS 8.2fixed in matrix-synapse 1.121.0-1 (forky)2024
CVE-2024-53863 [HIGH] CVE-2024-53863: matrix-synapse - Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1,...
Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option or processing a specially crafted request could trigger the decoding and thumbnail generation of uncommon image formats, potentially invoking external tools like Ghostscript for processing. This significantly expands the attack surface in a
debian
CVE-2021-41281P3HIGHCVSS 7.5fixed in matrix-synapse 1.47.1-1 (forky)2021
CVE-2021-41281 [HIGH] CVE-2021-41281: matrix-synapse - Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior t...
Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled can be tricked into downloading a file from a remote server into an arbitrary directory. No authentication is required for the affected endpoint. The last 2 directories and file name of the path are chosen rando
debian
CVE-2018-16515P3HIGHCVSS 8.8fixed in matrix-synapse 0.33.3.1-1 (forky)2018
CVE-2018-16515 [HIGH] CVE-2018-16515: matrix-synapse - Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possi...
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
Scope: local
forky: resolved (fixed in 0.33.3.1-1)
sid: resolved (fixed in 0.33.3.1-1)
debian
CVE-2019-5885P3HIGHCVSS 7.5fixed in matrix-synapse 0.34.1.1-1 (forky)2019
CVE-2019-5885 [HIGH] CVE-2019-5885: matrix-synapse - Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication para...
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
Scope: local
forky: resolved (fixed in 0.34.1.1-1)
sid: resolved (fixed in 0.34.1.1-1)
debian
CVE-2024-37302P3HIGHCVSS 7.5fixed in matrix-synapse 1.116.0-1 (forky)2024
CVE-2024-37302 [HIGH] CVE-2024-37302: matrix-synapse - Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are v...
Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where an unauthenticated adversary can induce Synapse to download and cache large amounts of remote media. The default rate limit strategy is insufficient to mitigate this. This can lead to a denial of service, ranging from further media uploads/do
debian
CVE-2020-26890P3HIGHCVSS 7.5fixed in matrix-synapse 1.20.0-1 (forky)2020
CVE-2020-26890 [HIGH] CVE-2020-26890: matrix-synapse - Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and...
Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing remote attackers to execute a denial of service attack against the federation and common Matrix clients. If such a malformed event is accepted into the room's state, the impact is long-lasting and is not fixed by a
debian
CVE-2024-52805P3HIGHCVSS 8.2fixed in matrix-synapse 1.121.0-1 (forky)2024
CVE-2024-52805 [HIGH] CVE-2024-52805: matrix-synapse - Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipar...
Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart
debian
CVE-2018-12291P3HIGHCVSS 7.5fixed in matrix-synapse 0.31.1+dfsg-1 (forky)2018
CVE-2018-12291 [HIGH] CVE-2018-12291: matrix-synapse - The on_get_missing_events function in handlers/federation.py in Matrix Synapse b...
The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rules were not applied correctly.
Scope: local
forky: resolved (fixed in 0.31.1+dfsg-1)
sid: resolved (fixed in 0.31.1+dfsg-1)
debian
CVE-2019-11842P3HIGHCVSS 7.5fixed in matrix-synapse 0.99.2-5 (forky)2019
CVE-2019-11842 [HIGH] CVE-2019-11842: matrix-synapse - An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3....
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.
Scope: local
forky: resolved (fixed in 0.99.2-5)
sid: resolved (fixed in 0.99.2-5)
debian
CVE-2019-18835P3CRITICALCVSS 9.8fixed in matrix-synapse 1.5.0-1 (forky)2019
CVE-2019-18835 [CRITICAL] CVE-2019-18835: matrix-synapse - Matrix Synapse before 1.5.0 mishandles signature checking on some federation API...
Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers.
Scope: local
forky: resolved (fixed in 1.5.0-1)
sid: resolved (fixed in 1.5.0-1)
debian
CVE-2022-31152P3MEDIUMCVSS 6.4fixed in matrix-synapse 1.63.0-1 (forky)2022
CVE-2022-31152 [MEDIUM] CVE-2022-31152: matrix-synapse - Synapse is an open-source Matrix homeserver written and maintained by the Matrix...
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specification specifies a list of [event authorization rules](https://spec.matrix.org/v1.2/rooms/v9/#authorization-rules) which must be checked when determining if an event should be accepted into a room. In versions of Synapse up to and including ver
debian
CVE-2022-31052P3MEDIUMCVSS 6.5fixed in matrix-synapse 1.61.1-1 (forky)2022
CVE-2022-31052 [MEDIUM] CVE-2022-31052: matrix-synapse - Synapse is an open source home server implementation for the Matrix chat network...
Synapse is an open source home server implementation for the Matrix chat network. In versions prior to 1.61.1 URL previews of some web pages can exhaust the available stack space for the Synapse process due to unbounded recursion. This is sometimes recoverable and leads to an error for the request causing the problem, but in other cases the Synapse process
debian
CVE-2018-12423P3HIGHCVSS 7.5fixed in matrix-synapse 0.31.2+dfsg-1 (forky)2018
CVE-2018-12423 [HIGH] CVE-2018-12423: matrix-synapse - In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m...
In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.
Scope: local
forky: resolved (fixed in 0.31.2+dfsg-1)
sid: resolved (fixed in 0.31.2+dfsg-1)
debian
CVE-2021-21332P3MEDIUMCVSS 6.9fixed in matrix-synapse 1.27.0-1 (forky)2021
CVE-2021-21332 [MEDIUM] CVE-2021-21332: matrix-synapse - Synapse is a Matrix reference homeserver written in python (pypi package matrix-...
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the password reset endpoint served via Synapse was vulnerable to cross-site scripting (XSS) attacks. The impact depends on the configuration of the domain that Synap
debian
CVE-2021-21393P3MEDIUMCVSS 5.3fixed in matrix-synapse 1.28.0-1 (forky)2021
CVE-2021-21393 [MEDIUM] CVE-2021-21393: matrix-synapse - Synapse is a Matrix reference homeserver written in python (pypi package matrix-...
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory lea
debian
CVE-2021-21394P3MEDIUMCVSS 5.3fixed in matrix-synapse 1.28.0-1 (forky)2021
CVE-2021-21394 [MEDIUM] CVE-2021-21394: matrix-synapse - Synapse is a Matrix reference homeserver written in python (pypi package matrix-...
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memory lea
debian
CVE-2024-31208P3MEDIUMCVSS 6.5fixed in matrix-synapse 1.103.0-2 (forky)2024
CVE-2024-31208 [MEDIUM] CVE-2024-31208: matrix-synapse - Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious...
Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in the V2 state resolution algorithm. This can induce high CPU consumption and accumulate excessive data in the database of such instances, resulting in a d
debian
CVE-2020-26257P4MEDIUMCVSS 6.5fixed in matrix-synapse 1.24.0-1 (forky)2020
CVE-2020-26257 [MEDIUM] CVE-2020-26257: matrix-synapse - Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is...
Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix. A malicious or poorly-implemented homeserver can inject malformed events into a room by specifying a different room id in the path of a `/send_join`, `/send_leave`, `/invite` or `/exchange_third_party_invite` request. This can
debian
1 / 3Next →