Debian Matrix-Synapse vulnerabilities
44 known vulnerabilities affecting debian/matrix-synapse.
Total CVEs
44
CISA KEV
0
Public exploits
0
Exploited in wild
2
Severity breakdown
CRITICAL1HIGH14MEDIUM22LOW7
Vulnerabilities
Page 3 of 3
CVE-2023-41335P4LOWCVSS 3.7fixed in matrix-synapse 1.93.0-1 (forky)2023
CVE-2023-41335 [LOW] CVE-2023-41335: matrix-synapse - Synapse is an open-source Matrix homeserver written and maintained by the Matrix...
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their passwords, the new credentials may be briefly held in the server database. While this doesn't grant the server any added capabilities—it already learns the users' passwords as part of the authentication process—it does disrupt the expectatio
debian
CVE-2021-39164P4LOWCVSS 3.1fixed in matrix-synapse 1.41.1-1 (forky)2021
CVE-2021-39164 [LOW] CVE-2021-39164: matrix-synapse - Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. I...
Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the membership (list of members, with their display names) of a room if they know the ID of the room. The vulnerability is limited to rooms with `shared` history visibility. Furthermore, the unauthorised user must be using
debian
CVE-2021-39163P4LOWCVSS 3.1fixed in matrix-synapse 1.41.1-1 (forky)2021
CVE-2021-39163 [LOW] CVE-2021-39163: matrix-synapse - Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. I...
Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the name, avatar, topic and number of members of a room if they know the ID of the room. This vulnerability is limited to homeservers where the vulnerable homeserver is in the room and untrusted users are permitted to creat
debian
CVE-2026-45076P4MEDIUM≥ 0, < 1.152.12026-05-14
CVE-2026-45076 [MEDIUM] CWE-20 Synapse pagination Denial of Service
Synapse pagination Denial of Service
### Impact
In federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full history to paginating clients.
Clients could therefore fail to display room history.
### Patches
Update to Synapse 1.152.1 or later.
### Workarounds
There are no known workarounds for this issue.
### Identifiers
- ELEMENTSEC-2025-1636
### For more inform
ghsa
← Previous3 / 3