Vulnerabilities
CVE-2019-5885
CVE-2019-5885
CVE-2026-45078
Synapse CPU starvation (Denial of Service)
CVE-2026-45076
Synapse pagination Denial of Service
CVE-2024-37302
Synapse denial of service through media disk space consumption
CVE-2024-37303
Synapse's unauthenticated writes to the media repository allow planting of problematic content
CVE-2026-45076
CVE-2026-45076
CVE-2026-45078
CVE-2026-45078
CVE-2024-37303
CVE-2024-37303
CVE-2024-37302
CVE-2024-37302
CVE-2021-29471
Denial of service attack via push rule patterns in matrix-synapse
CVE-2021-41281
Path traversal in Matrix Synapse
CVE-2021-21393
Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints
CVE-2020-26891
Cross-site scripting (XSS) vulnerability in the fallback authentication endpoint
CVE-2021-21273
Open redirects on some federation and push requests
CVE-2020-26890
Denial of service attack due to invalid JSON
CVE-2021-21392
Open redirect via transitional IPv6 addresses on dual-stack networks
CVE-2021-21274
Denial of service attack via .well-known lookups
CVE-2021-21332
Cross-site scripting (XSS) vulnerability in the password reset endpoint
CVE-2021-21333
HTML injection in email and account expiry notifications
CVE-2021-39163
Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.
CVE-2021-39164
Improper authorisation of members discloses room membership to non-members
CVE-2021-21394
Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints
CVE-2020-26257
Denial of service attack via incorrect parameters in Matrix Synapse
CVE-2021-41281
CVE-2021-41281
CVE-2021-39164
CVE-2021-39164
CVE-2021-39163
CVE-2021-39163
CVE-2025-30355
Synapse vulnerable to federation denial of service via malformed events
CVE-2025-61672
Synapse's invalid device keys degrade federation functionality
CVE-2019-18835
Improper Verification of Cryptographic Signature in matrix-synapse
CVE-2023-43796
Synapse vulnerable to leak of remote user device information
CVE-2023-32323
Synapse Outgoing federation to specific hosts can be disabled by sending malicious invites
CVE-2024-53867
Synapse Matrix has a partial room state leak via Sliding Sync
CVE-2024-53863
Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
CVE-2024-52815
Synapse allows a a malformed invite to break the invitee's `/sync`
CVE-2024-52805
Synapse allows unsupported content types to lead to memory exhaustion
GHSA-7h5v-85w9-pq6c
Denial of service (via resource exhaustion) due to improper input validation in third-party identifier endpoint
CVE-2023-32683
Synapse has URL deny list bypass via oEmbed and image URLs when generating previews
CVE-2023-41335
matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes
CVE-2022-31152
Denial of service due to incorrect application of event authorization rules
CVE-2022-39374
Synapse Denial of service due to incorrect application of event authorization rules during state resolution
CVE-2019-11842
matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG
CVE-2022-31052
URL previews of unusual or maliciously-crafted pages can crash Synapse media repositories or Synapse monoliths
CVE-2022-39335
Synapse does not apply enough checks to servers requesting auth events of events in a room
CVE-2023-42453
matrix-synapse vulnerable to improper validation of receipts allows forged read receipts
CVE-2023-45129
matrix-synapse vulnerable to denial of service due to malicious server ACL events
CVE-2023-32682
Synapse has improper checks for deactivated users during login
CVE-2019-5885
Matrix Synapse Predictable Secret Key
CVE-2024-31208
Synapse V2 state resolution weakness allows Denial of Service (DoS)
CVE-2024-31208
CVE-2024-31208
CVE-2022-41952
Uncontrolled Resource Consumption in Matrix Synapse
CVE-2023-43796
CVE-2023-43796
CVE-2023-45129
CVE-2023-45129
CVE-2023-42453
CVE-2023-42453
CVE-2023-41335
CVE-2023-41335
CVE-2023-32683
CVE-2023-32683
CVE-2023-32682
CVE-2023-32682
CVE-2023-32323
CVE-2023-32323
CVE-2022-39374
CVE-2022-39374
CVE-2022-39335
CVE-2022-39335
CVE-2022-31152
CVE-2022-31152
CVE-2022-31052
CVE-2022-31052
CVE-2021-29471
CVE-2021-29471
CVE-2021-21394
CVE-2021-21394
CVE-2021-21393
CVE-2021-21393
CVE-2021-21392
CVE-2021-21392
CVE-2021-21333
CVE-2021-21333
CVE-2021-21332
CVE-2021-21332
CVE-2021-21274
CVE-2021-21274
CVE-2021-21273
CVE-2021-21273
CVE-2020-26891
CVE-2020-26891
CVE-2020-26890
CVE-2020-26890
CVE-2020-26257
CVE-2020-26257
CVE-2019-18835
CVE-2019-18835
CVE-2019-11842
CVE-2019-11842
CVE-2018-16515
Matrix Synapse Improper Signature Validation
CVE-2018-12423
Matrix Synapse Authorization Error
CVE-2018-12291
Matrix Synapse Security Filtering Flaw
CVE-2018-10657
Matrix Synapse DoS
Ready to move
Start Securing
Free, no credit card | First findings in minutes