Dependency scanning
Check whether matrix-synapse is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-45078
Synapse CPU starvation (Denial of Service)
CVE-2026-45076
Synapse pagination Denial of Service
CVE-2024-31208
Synapse V2 state resolution weakness allows Denial of Service (DoS)
CVE-2023-41335
matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes
CVE-2023-32682
Synapse has improper checks for deactivated users during login
CVE-2023-45129
matrix-synapse vulnerable to denial of service due to malicious server ACL events
CVE-2023-42453
matrix-synapse vulnerable to improper validation of receipts allows forged read receipts
CVE-2023-43796
Synapse vulnerable to leak of remote user device information
CVE-2021-21274
Denial of service attack via .well-known lookups
CVE-2020-26257
Denial of service attack via incorrect parameters in Matrix Synapse
CVE-2019-11842
CVE-2019-11842
CVE-2019-11842
matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG
CVE-2021-21394
Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints
CVE-2020-26891
Cross-site scripting (XSS) vulnerability in the fallback authentication endpoint
CVE-2020-26890
Denial of service attack due to invalid JSON
CVE-2021-39163
Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.
CVE-2021-39164
Improper authorisation of members discloses room membership to non-members
CVE-2021-21392
Open redirect via transitional IPv6 addresses on dual-stack networks
CVE-2021-21393
Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints
CVE-2021-41281
Path traversal in Matrix Synapse
CVE-2021-21273
Open redirects on some federation and push requests
CVE-2021-21332
Cross-site scripting (XSS) vulnerability in the password reset endpoint
CVE-2021-21333
HTML injection in email and account expiry notifications
CVE-2021-29471
Denial of service attack via push rule patterns in matrix-synapse
CVE-2024-53867
Synapse Matrix has a partial room state leak via Sliding Sync
CVE-2024-52815
Synapse allows a a malformed invite to break the invitee's `/sync`
CVE-2024-52805
Synapse allows unsupported content types to lead to memory exhaustion
CVE-2024-53863
Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
CVE-2025-30355
Synapse vulnerable to federation denial of service via malformed events
CVE-2025-61672
Synapse's invalid device keys degrade federation functionality
CVE-2024-52815
Synapse allows a a malformed invite to break the invitee's `/sync`
CVE-2024-53867
Synapse Matrix has a partial room state leak via Sliding Sync
CVE-2024-53863
Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
CVE-2024-52805
Synapse allows unsupported content types to lead to memory exhaustion
CVE-2025-30355
Synapse vulnerable to federation denial of service via malformed events
CVE-2025-61672
Synapse's invalid device keys degrade federation functionality
CVE-2018-16515
Matrix Synapse Improper Signature Validation
CVE-2018-12423
Matrix Synapse Authorization Error
CVE-2018-10657
Matrix Synapse DoS
CVE-2018-10657
Matrix Synapse DoS
CVE-2018-12423
Matrix Synapse Authorization Error
CVE-2018-16515
Matrix Synapse Improper Signature Validation
CVE-2018-12291
Matrix Synapse Security Filtering Flaw
CVE-2022-41952
Uncontrolled Resource Consumption in Matrix Synapse
CVE-2022-41952
Uncontrolled Resource Consumption in Matrix Synapse
CVE-2018-12291
Matrix Synapse Security Filtering Flaw
CVE-2019-5885
CVE-2019-5885
CVE-2024-37302
Synapse denial of service through media disk space consumption
CVE-2024-37303
Synapse's unauthenticated writes to the media repository allow planting of problematic content
CVE-2026-45076
CVE-2026-45076
CVE-2026-45078
CVE-2026-45078
CVE-2024-37303
CVE-2024-37303
CVE-2024-37302
CVE-2024-37302
CVE-2021-41281
CVE-2021-41281
CVE-2021-39164
CVE-2021-39164
CVE-2021-39163
CVE-2021-39163
CVE-2019-18835
Improper Verification of Cryptographic Signature in matrix-synapse
CVE-2023-32323
Synapse Outgoing federation to specific hosts can be disabled by sending malicious invites
GHSA-7h5v-85w9-pq6c
Denial of service (via resource exhaustion) due to improper input validation in third-party identifier endpoint
CVE-2023-32683
Synapse has URL deny list bypass via oEmbed and image URLs when generating previews
CVE-2022-31152
Denial of service due to incorrect application of event authorization rules
CVE-2022-39374
Synapse Denial of service due to incorrect application of event authorization rules during state resolution
CVE-2022-31052
URL previews of unusual or maliciously-crafted pages can crash Synapse media repositories or Synapse monoliths
CVE-2022-39335
Synapse does not apply enough checks to servers requesting auth events of events in a room
CVE-2019-5885
Matrix Synapse Predictable Secret Key
CVE-2024-31208
CVE-2024-31208
CVE-2023-43796
CVE-2023-43796
CVE-2023-45129
CVE-2023-45129
CVE-2023-42453
CVE-2023-42453
CVE-2023-41335
CVE-2023-41335
CVE-2023-32683
CVE-2023-32683
CVE-2023-32682
CVE-2023-32682
CVE-2023-32323
CVE-2023-32323
CVE-2022-39374
CVE-2022-39374
CVE-2022-39335
CVE-2022-39335
CVE-2022-31152
CVE-2022-31152
CVE-2022-31052
CVE-2022-31052
CVE-2021-29471
CVE-2021-29471
CVE-2021-21394
CVE-2021-21394
CVE-2021-21393
CVE-2021-21393
CVE-2021-21392
CVE-2021-21392
CVE-2021-21333
CVE-2021-21333
CVE-2021-21332
CVE-2021-21332
CVE-2021-21274
CVE-2021-21274
CVE-2021-21273
CVE-2021-21273
CVE-2020-26891
CVE-2020-26891
CVE-2020-26890
CVE-2020-26890
CVE-2020-26257
CVE-2020-26257
CVE-2019-18835
CVE-2019-18835
Browse more PyPI advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes