Launch Week Day 1: Announcing Security Design Review
pypi

matrix-synapse

View on pypi registry
78 Total advisories
78 Vulnerabilities
0 Malware

Vulnerabilities

UNKNOWN
PyPI

CVE-2019-5885

CVE-2019-5885

MEDIUM 5.5
PyPI

CVE-2026-45078

Synapse CPU starvation (Denial of Service)

UNKNOWN
PyPI

CVE-2026-45076

Synapse pagination Denial of Service

HIGH 7.5
PyPI

CVE-2024-37302

Synapse denial of service through media disk space consumption

MEDIUM 5.3
PyPI

CVE-2024-37303

Synapse's unauthenticated writes to the media repository allow planting of problematic content

LOW 2.7
PyPI

CVE-2026-45076

CVE-2026-45076

MEDIUM 5.5
PyPI

CVE-2026-45078

CVE-2026-45078

MEDIUM 5.3
PyPI

CVE-2024-37303

CVE-2024-37303

HIGH 7.5
PyPI

CVE-2024-37302

CVE-2024-37302

LOW 3.7
PyPI

CVE-2021-29471

Denial of service attack via push rule patterns in matrix-synapse

HIGH 7.5
PyPI

CVE-2021-41281

Path traversal in Matrix Synapse

MEDIUM 5.3
PyPI

CVE-2021-21393

Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints

MEDIUM 6.1
PyPI

CVE-2020-26891

Cross-site scripting (XSS) vulnerability in the fallback authentication endpoint

LOW 3.1
PyPI

CVE-2021-21273

Open redirects on some federation and push requests

HIGH 7.5
PyPI

CVE-2020-26890

Denial of service attack due to invalid JSON

MEDIUM 6.3
PyPI

CVE-2021-21392

Open redirect via transitional IPv6 addresses on dual-stack networks

MEDIUM 4.3
PyPI

CVE-2021-21274

Denial of service attack via .well-known lookups

MEDIUM 6.9
PyPI

CVE-2021-21332

Cross-site scripting (XSS) vulnerability in the password reset endpoint

MEDIUM 6.1
PyPI

CVE-2021-21333

HTML injection in email and account expiry notifications

LOW 3.1
PyPI

CVE-2021-39163

Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.

LOW 3.1
PyPI

CVE-2021-39164

Improper authorisation of members discloses room membership to non-members

MEDIUM 5.3
PyPI

CVE-2021-21394

Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints

MEDIUM 6.5
PyPI

CVE-2020-26257

Denial of service attack via incorrect parameters in Matrix Synapse

UNKNOWN
PyPI

CVE-2021-41281

CVE-2021-41281

UNKNOWN
PyPI

CVE-2021-39164

CVE-2021-39164

UNKNOWN
PyPI

CVE-2021-39163

CVE-2021-39163

HIGH 7.1
PyPI

CVE-2025-30355

Synapse vulnerable to federation denial of service via malformed events

UNKNOWN
PyPI

CVE-2025-61672

Synapse's invalid device keys degrade federation functionality

HIGH 8.6
PyPI

CVE-2019-18835

Improper Verification of Cryptographic Signature in matrix-synapse

MEDIUM 5.3
PyPI

CVE-2023-43796

Synapse vulnerable to leak of remote user device information

MEDIUM 5.0
PyPI

CVE-2023-32323

Synapse Outgoing federation to specific hosts can be disabled by sending malicious invites

MEDIUM 4.3
PyPI

CVE-2024-53867

Synapse Matrix has a partial room state leak via Sliding Sync

UNKNOWN
PyPI

CVE-2024-53863

Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders

UNKNOWN
PyPI

CVE-2024-52815

Synapse allows a a malformed invite to break the invitee's `/sync`

UNKNOWN
PyPI

CVE-2024-52805

Synapse allows unsupported content types to lead to memory exhaustion

UNKNOWN
PyPI

GHSA-7h5v-85w9-pq6c

Denial of service (via resource exhaustion) due to improper input validation in third-party identifier endpoint

LOW 3.5
PyPI

CVE-2023-32683

Synapse has URL deny list bypass via oEmbed and image URLs when generating previews

LOW 3.7
PyPI

CVE-2023-41335

matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes

HIGH 7.5
PyPI

CVE-2022-31152

Denial of service due to incorrect application of event authorization rules

MEDIUM 6.5
PyPI

CVE-2022-39374

Synapse Denial of service due to incorrect application of event authorization rules during state resolution

HIGH 7.5
PyPI

CVE-2019-11842

matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG

MEDIUM 6.5
PyPI

CVE-2022-31052

URL previews of unusual or maliciously-crafted pages can crash Synapse media repositories or Synapse monoliths

MEDIUM 5.0
PyPI

CVE-2022-39335

Synapse does not apply enough checks to servers requesting auth events of events in a room

LOW 3.1
PyPI

CVE-2023-42453

matrix-synapse vulnerable to improper validation of receipts allows forged read receipts

MEDIUM 4.9
PyPI

CVE-2023-45129

matrix-synapse vulnerable to denial of service due to malicious server ACL events

MEDIUM 5.4
PyPI

CVE-2023-32682

Synapse has improper checks for deactivated users during login

HIGH 7.5
PyPI

CVE-2019-5885

Matrix Synapse Predictable Secret Key

MEDIUM 6.5
PyPI

CVE-2024-31208

Synapse V2 state resolution weakness allows Denial of Service (DoS)

UNKNOWN
PyPI

CVE-2024-31208

CVE-2024-31208

MEDIUM 5.3
PyPI

CVE-2022-41952

Uncontrolled Resource Consumption in Matrix Synapse

MEDIUM 5.3
PyPI

CVE-2023-43796

CVE-2023-43796

MEDIUM 4.9
PyPI

CVE-2023-45129

CVE-2023-45129

MEDIUM 4.3
PyPI

CVE-2023-42453

CVE-2023-42453

LOW 3.7
PyPI

CVE-2023-41335

CVE-2023-41335

UNKNOWN
PyPI

CVE-2023-32683

CVE-2023-32683

UNKNOWN
PyPI

CVE-2023-32682

CVE-2023-32682

UNKNOWN
PyPI

CVE-2023-32323

CVE-2023-32323

UNKNOWN
PyPI

CVE-2022-39374

CVE-2022-39374

UNKNOWN
PyPI

CVE-2022-39335

CVE-2022-39335

UNKNOWN
PyPI

CVE-2022-31152

CVE-2022-31152

UNKNOWN
PyPI

CVE-2022-31052

CVE-2022-31052

UNKNOWN
PyPI

CVE-2021-29471

CVE-2021-29471

UNKNOWN
PyPI

CVE-2021-21394

CVE-2021-21394

UNKNOWN
PyPI

CVE-2021-21393

CVE-2021-21393

UNKNOWN
PyPI

CVE-2021-21392

CVE-2021-21392

UNKNOWN
PyPI

CVE-2021-21333

CVE-2021-21333

UNKNOWN
PyPI

CVE-2021-21332

CVE-2021-21332

UNKNOWN
PyPI

CVE-2021-21274

CVE-2021-21274

UNKNOWN
PyPI

CVE-2021-21273

CVE-2021-21273

UNKNOWN
PyPI

CVE-2020-26891

CVE-2020-26891

UNKNOWN
PyPI

CVE-2020-26890

CVE-2020-26890

UNKNOWN
PyPI

CVE-2020-26257

CVE-2020-26257

UNKNOWN
PyPI

CVE-2019-18835

CVE-2019-18835

UNKNOWN
PyPI

CVE-2019-11842

CVE-2019-11842

HIGH 8.8
PyPI

CVE-2018-16515

Matrix Synapse Improper Signature Validation

HIGH 7.5
PyPI

CVE-2018-12423

Matrix Synapse Authorization Error

HIGH 7.5
PyPI

CVE-2018-12291

Matrix Synapse Security Filtering Flaw

HIGH 7.5
PyPI

CVE-2018-10657

Matrix Synapse DoS

Ready to move

Start Securing

Free, no credit card | First findings in minutes