Debian Matrix-Synapse vulnerabilities
44 known vulnerabilities affecting debian/matrix-synapse.
Total CVEs
44
CISA KEV
0
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL1HIGH14MEDIUM22LOW7
Vulnerabilities
Page 2 of 3
CVE-2021-21392P4MEDIUMCVSS 6.3fixed in matrix-synapse 1.28.0-1 (forky)2021
CVE-2021-21392 [MEDIUM] CVE-2021-21392: matrix-synapse - Synapse is a Matrix reference homeserver written in python (pypi package matrix-...
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 requests to user provided domains were not restricted to external IP addresses when transitional IPv6 addresses were used. Outbound requests to federation, identity s
debian
CVE-2025-61672P4MEDIUMCVSS 5.3fixed in matrix-synapse 1.139.2-1 (forky)2025
CVE-2025-61672 [MEDIUM] CVE-2025-61672: matrix-synapse - Synapse is an open source Matrix homeserver implementation. Lack of validation f...
Synapse is an open source Matrix homeserver implementation. Lack of validation for device keys in Synapse before 1.138.3 and in Synapse 1.139.0 allow an attacker registered on the victim homeserver to degrade federation functionality, unpredictably breaking outbound federation to other homeservers. The issue is patched in Synapse 1.138.3, 1.138.4, 1.139.1,
debian
CVE-2022-39374P4MEDIUMCVSS 6.5fixed in matrix-synapse 1.68.0-1 (forky)2022
CVE-2022-39374 [MEDIUM] CVE-2022-39374: matrix-synapse - Synapse is an open-source Matrix homeserver written and maintained by the Matrix...
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting previously rejected events into its view of the current state of that room. This can be exploited in a way that causes all further m
debian
CVE-2024-37303P4MEDIUMCVSS 5.3fixed in matrix-synapse 1.116.0-1 (forky)2024
CVE-2024-37303 [MEDIUM] CVE-2024-37303: matrix-synapse - Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows...
Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media from a remote homeserver to the local media repository. Such content then also becomes available for download from the local homeserver in an unauthenticated way. The implication i
debian
CVE-2021-21273P4LOWCVSS 3.1fixed in matrix-synapse 1.25.0-1 (forky)2021
CVE-2021-21273 [LOW] CVE-2021-21273: matrix-synapse - Synapse is a Matrix reference homeserver written in python (pypi package matrix-...
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, requests to user provided domains were not restricted to external IP addresses when calculating the key validity for third-party invite events and sending push notifica
debian
CVE-2023-32682P4MEDIUMCVSS 5.4fixed in matrix-synapse 1.90.0-1 (forky)2023
CVE-2023-32682 [MEDIUM] CVE-2023-32682: matrix-synapse - Synapse is a Matrix protocol homeserver written in Python with the Twisted frame...
Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. In affected versions it may be possible for a deactivated user to login when using uncommon configurations. This only applies if any of the following are true: 1. JSON Web Tokens are enabled for login via the `jwt_config.enabled` configuration setting. 2. The local passwor
debian
CVE-2021-21274P4MEDIUMCVSS 4.3fixed in matrix-synapse 1.25.0-1 (forky)2021
CVE-2021-21274 [MEDIUM] CVE-2021-21274: matrix-synapse - Synapse is a Matrix reference homeserver written in python (pypi package matrix-...
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, a malicious homeserver could redirect requests to their .well-known file to a large file. This can lead to a denial of service attack where homeservers will consume
debian
CVE-2020-26891P4MEDIUMCVSS 6.1fixed in matrix-synapse 1.21.1-1 (forky)2020
CVE-2020-26891 [MEDIUM] CVE-2020-26891: matrix-synapse - AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsa...
AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsafe interpolation of the session GET parameter. This allows a remote attacker to execute an XSS attack on the domain Synapse is hosted on, by supplying the victim user with a malicious URL to the /_matrix/client/r0/auth/*/fallback/web or /_matrix/client/unstable/auth/*/fallback/w
debian
CVE-2021-21333P4MEDIUMCVSS 6.1fixed in matrix-synapse 1.27.0-1 (forky)2021
CVE-2021-21333 [MEDIUM] CVE-2021-21333: matrix-synapse - Synapse is a Matrix reference homeserver written in python (pypi package matrix-...
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the notification emails sent for notifications for missed messages or for an expiring account are subject to HTML injection. In the case of the notification for miss
debian
CVE-2024-52815P4HIGHCVSS 8.7fixed in matrix-synapse 1.121.0-1 (forky)2024
CVE-2024-52815 [HIGH] CVE-2024-52815: matrix-synapse - Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fai...
Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user's /sync functionality. Synapse 1.120.1 rejects such invalid invites received over federation and restores the abi
debian
CVE-2022-39335P4MEDIUMCVSS 5.0fixed in matrix-synapse 1.69.0-1 (forky)2022
CVE-2022-39335 [MEDIUM] CVE-2022-39335: matrix-synapse - Synapse is an open-source Matrix homeserver written and maintained by the Matrix...
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix Federation API allows remote homeservers to request the authorization events in a room. This is necessary so that a homeserver receiving some events can validate that those events are legitimate and permitted in their room. However, in versions of Syn
debian
CVE-2023-32683P4LOWCVSS 3.5fixed in matrix-synapse 1.90.0-1 (forky)2023
CVE-2023-32683 [LOW] CVE-2023-32683: matrix-synapse - Synapse is a Matrix protocol homeserver written in Python with the Twisted frame...
Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL can bypass the `url_preview_url_blacklist` setting potentially allowing server side request forgery or bypassing network policies. Impact is limited to IP addresses allowed by the `url_preview_ip_range_blacklist` setting (by default this only
debian
CVE-2021-29471P4LOWCVSS 3.7fixed in matrix-synapse 1.33.2-1 (forky)2021
CVE-2021-29471 [LOW] CVE-2021-29471: matrix-synapse - Synapse is a Matrix reference homeserver written in python (pypi package matrix-...
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.33.2 "Push rules" can specify conditions under which they will match, including `event_match`, which matches event content against a pattern including wildcards. Certain patt
debian
CVE-2023-43796P4MEDIUMCVSS 5.3fixed in matrix-synapse 1.95.1-1 (forky)2023
CVE-2023-43796 [MEDIUM] CVE-2023-43796: matrix-synapse - Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0r...
Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver. System administrators are encouraged to upgrade to Synapse 1.95.1 or 1.96.0rc1 to receive a patch. As a workaround, the `federation_do
debian
CVE-2022-41952P4MEDIUMCVSS 6.5fixed in matrix-synapse 1.53.0-1 (forky)2022
CVE-2022-41952 [MEDIUM] CVE-2022-41952: matrix-synapse - Synapse before 1.52.0 with URL preview functionality enabled will attempt to gen...
Synapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs without properly limiting connection time. Connections will only be terminated after `max_spider_size` (default: 10M) bytes have been downloaded, which can in some cases lead to long-lived connections towards the streaming media server (f
debian
CVE-2023-32323P4MEDIUMCVSS 5.0fixed in matrix-synapse 1.74.0-1 (forky)2023
CVE-2023-32323 [MEDIUM] CVE-2023-32323: matrix-synapse - Synapse is an open-source Matrix homeserver written and maintained by the Matrix...
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. A malicious user on a Synapse homeserver X with permission to create certain state events can disable outbound federation from X to an arbitrary homeserver Y. Synapse instances with federation disabled are not affected. In versions of Synapse up to and including
debian
CVE-2023-45129P4MEDIUMCVSS 4.9fixed in matrix-synapse 1.94.0-1 (forky)2023
CVE-2023-45129 [MEDIUM] CVE-2023-45129: matrix-synapse - Synapse is an open-source Matrix homeserver written and maintained by the Matrix...
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service. Homeservers running on a closed federation (which presumably do not need to use server ACLs) are not affected. Serv
debian
CVE-2023-42453P4LOWCVSS 3.1fixed in matrix-synapse 1.93.0-1 (forky)2023
CVE-2023-42453 [LOW] CVE-2023-42453: matrix-synapse - Synapse is an open-source Matrix homeserver written and maintained by the Matrix...
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users were able to forge read receipts for any event (if they knew the room ID and event ID). Note that the users were not able to view the events, but simply mark it as read. This could be confusing as clients will show the event as read by the user, even if they
debian
CVE-2026-45078P4HIGH≥ 0, < 1.152.12026-05-14
CVE-2026-45078 [HIGH] CWE-400 Synapse CPU starvation (Denial of Service)
Synapse CPU starvation (Denial of Service)
### Impact
Local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied service.
Homeservers that trust all their local users are not at risk.
### Patches
Update to Synapse 1.152.1 or later.
### Workarounds
If Synapse is deployed behind a reverse proxy, the reverse proxy could be configured t
ghsa
CVE-2024-53867P4MEDIUMCVSS 4.3fixed in matrix-synapse 1.121.0-1 (forky)2024
CVE-2024-53867 [MEDIUM] CVE-2024-53867: matrix-synapse - Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse...
Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room. Non-state events, like messages, are unaffected. This vulnerability is fixed in 1.120.1.
Scope: local
forky: resolved (fixed in 1.121.0-1)
sid: resolved (fixed in 1.121.0-1
debian