pypi

matrix-synapse

View on pypi registry
89 Total advisories
89 Vulnerabilities
0 Malware

Dependency scanning

Check whether matrix-synapse is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 5.5
PyPI

CVE-2026-45078

Synapse CPU starvation (Denial of Service)

UNKNOWN
PyPI

CVE-2026-45076

Synapse pagination Denial of Service

MEDIUM 6.5
PyPI

CVE-2024-31208

Synapse V2 state resolution weakness allows Denial of Service (DoS)

LOW 3.7
PyPI

CVE-2023-41335

matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes

MEDIUM 5.4
PyPI

CVE-2023-32682

Synapse has improper checks for deactivated users during login

MEDIUM 4.9
PyPI

CVE-2023-45129

matrix-synapse vulnerable to denial of service due to malicious server ACL events

LOW 3.1
PyPI

CVE-2023-42453

matrix-synapse vulnerable to improper validation of receipts allows forged read receipts

MEDIUM 5.3
PyPI

CVE-2023-43796

Synapse vulnerable to leak of remote user device information

MEDIUM 4.3
PyPI

CVE-2021-21274

Denial of service attack via .well-known lookups

MEDIUM 6.5
PyPI

CVE-2020-26257

Denial of service attack via incorrect parameters in Matrix Synapse

UNKNOWN
PyPI

CVE-2019-11842

CVE-2019-11842

HIGH 7.5
PyPI

CVE-2019-11842

matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG

MEDIUM 5.3
PyPI

CVE-2021-21394

Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints

MEDIUM 6.1
PyPI

CVE-2020-26891

Cross-site scripting (XSS) vulnerability in the fallback authentication endpoint

HIGH 7.5
PyPI

CVE-2020-26890

Denial of service attack due to invalid JSON

LOW 3.1
PyPI

CVE-2021-39163

Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.

LOW 3.1
PyPI

CVE-2021-39164

Improper authorisation of members discloses room membership to non-members

MEDIUM 6.3
PyPI

CVE-2021-21392

Open redirect via transitional IPv6 addresses on dual-stack networks

MEDIUM 5.3
PyPI

CVE-2021-21393

Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints

HIGH 7.5
PyPI

CVE-2021-41281

Path traversal in Matrix Synapse

LOW 3.1
PyPI

CVE-2021-21273

Open redirects on some federation and push requests

MEDIUM 6.9
PyPI

CVE-2021-21332

Cross-site scripting (XSS) vulnerability in the password reset endpoint

MEDIUM 6.1
PyPI

CVE-2021-21333

HTML injection in email and account expiry notifications

LOW 3.7
PyPI

CVE-2021-29471

Denial of service attack via push rule patterns in matrix-synapse

MEDIUM 4.3
PyPI

CVE-2024-53867

Synapse Matrix has a partial room state leak via Sliding Sync

UNKNOWN
PyPI

CVE-2024-52815

Synapse allows a a malformed invite to break the invitee's `/sync`

UNKNOWN
PyPI

CVE-2024-52805

Synapse allows unsupported content types to lead to memory exhaustion

UNKNOWN
PyPI

CVE-2024-53863

Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders

HIGH 7.1
PyPI

CVE-2025-30355

Synapse vulnerable to federation denial of service via malformed events

UNKNOWN
PyPI

CVE-2025-61672

Synapse's invalid device keys degrade federation functionality

UNKNOWN
PyPI

CVE-2024-52815

Synapse allows a a malformed invite to break the invitee's `/sync`

MEDIUM 4.3
PyPI

CVE-2024-53867

Synapse Matrix has a partial room state leak via Sliding Sync

UNKNOWN
PyPI

CVE-2024-53863

Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders

UNKNOWN
PyPI

CVE-2024-52805

Synapse allows unsupported content types to lead to memory exhaustion

HIGH 7.1
PyPI

CVE-2025-30355

Synapse vulnerable to federation denial of service via malformed events

UNKNOWN
PyPI

CVE-2025-61672

Synapse's invalid device keys degrade federation functionality

HIGH 8.8
PyPI

CVE-2018-16515

Matrix Synapse Improper Signature Validation

HIGH 7.5
PyPI

CVE-2018-12423

Matrix Synapse Authorization Error

HIGH 7.5
PyPI

CVE-2018-10657

Matrix Synapse DoS

HIGH 7.5
PyPI

CVE-2018-10657

Matrix Synapse DoS

HIGH 7.5
PyPI

CVE-2018-12423

Matrix Synapse Authorization Error

HIGH 8.8
PyPI

CVE-2018-16515

Matrix Synapse Improper Signature Validation

HIGH 7.5
PyPI

CVE-2018-12291

Matrix Synapse Security Filtering Flaw

MEDIUM 5.3
PyPI

CVE-2022-41952

Uncontrolled Resource Consumption in Matrix Synapse

MEDIUM 5.3
PyPI

CVE-2022-41952

Uncontrolled Resource Consumption in Matrix Synapse

HIGH 7.5
PyPI

CVE-2018-12291

Matrix Synapse Security Filtering Flaw

UNKNOWN
PyPI

CVE-2019-5885

CVE-2019-5885

HIGH 7.5
PyPI

CVE-2024-37302

Synapse denial of service through media disk space consumption

MEDIUM 5.3
PyPI

CVE-2024-37303

Synapse's unauthenticated writes to the media repository allow planting of problematic content

LOW 2.7
PyPI

CVE-2026-45076

CVE-2026-45076

MEDIUM 5.5
PyPI

CVE-2026-45078

CVE-2026-45078

MEDIUM 5.3
PyPI

CVE-2024-37303

CVE-2024-37303

HIGH 7.5
PyPI

CVE-2024-37302

CVE-2024-37302

UNKNOWN
PyPI

CVE-2021-41281

CVE-2021-41281

UNKNOWN
PyPI

CVE-2021-39164

CVE-2021-39164

UNKNOWN
PyPI

CVE-2021-39163

CVE-2021-39163

HIGH 8.6
PyPI

CVE-2019-18835

Improper Verification of Cryptographic Signature in matrix-synapse

MEDIUM 5.0
PyPI

CVE-2023-32323

Synapse Outgoing federation to specific hosts can be disabled by sending malicious invites

UNKNOWN
PyPI

GHSA-7h5v-85w9-pq6c

Denial of service (via resource exhaustion) due to improper input validation in third-party identifier endpoint

LOW 3.5
PyPI

CVE-2023-32683

Synapse has URL deny list bypass via oEmbed and image URLs when generating previews

HIGH 7.5
PyPI

CVE-2022-31152

Denial of service due to incorrect application of event authorization rules

MEDIUM 6.5
PyPI

CVE-2022-39374

Synapse Denial of service due to incorrect application of event authorization rules during state resolution

MEDIUM 6.5
PyPI

CVE-2022-31052

URL previews of unusual or maliciously-crafted pages can crash Synapse media repositories or Synapse monoliths

MEDIUM 5.0
PyPI

CVE-2022-39335

Synapse does not apply enough checks to servers requesting auth events of events in a room

HIGH 7.5
PyPI

CVE-2019-5885

Matrix Synapse Predictable Secret Key

UNKNOWN
PyPI

CVE-2024-31208

CVE-2024-31208

MEDIUM 5.3
PyPI

CVE-2023-43796

CVE-2023-43796

MEDIUM 4.9
PyPI

CVE-2023-45129

CVE-2023-45129

MEDIUM 4.3
PyPI

CVE-2023-42453

CVE-2023-42453

LOW 3.7
PyPI

CVE-2023-41335

CVE-2023-41335

UNKNOWN
PyPI

CVE-2023-32683

CVE-2023-32683

UNKNOWN
PyPI

CVE-2023-32682

CVE-2023-32682

UNKNOWN
PyPI

CVE-2023-32323

CVE-2023-32323

UNKNOWN
PyPI

CVE-2022-39374

CVE-2022-39374

UNKNOWN
PyPI

CVE-2022-39335

CVE-2022-39335

UNKNOWN
PyPI

CVE-2022-31152

CVE-2022-31152

UNKNOWN
PyPI

CVE-2022-31052

CVE-2022-31052

UNKNOWN
PyPI

CVE-2021-29471

CVE-2021-29471

UNKNOWN
PyPI

CVE-2021-21394

CVE-2021-21394

UNKNOWN
PyPI

CVE-2021-21393

CVE-2021-21393

UNKNOWN
PyPI

CVE-2021-21392

CVE-2021-21392

UNKNOWN
PyPI

CVE-2021-21333

CVE-2021-21333

UNKNOWN
PyPI

CVE-2021-21332

CVE-2021-21332

UNKNOWN
PyPI

CVE-2021-21274

CVE-2021-21274

UNKNOWN
PyPI

CVE-2021-21273

CVE-2021-21273

UNKNOWN
PyPI

CVE-2020-26891

CVE-2020-26891

UNKNOWN
PyPI

CVE-2020-26890

CVE-2020-26890

UNKNOWN
PyPI

CVE-2020-26257

CVE-2020-26257

UNKNOWN
PyPI

CVE-2019-18835

CVE-2019-18835

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes