HIGH 8.8 PyPI

Matrix Synapse Improper Signature Validation

GHSA-fmvh-rvq5-hhjx · CVE-2018-16515 · PYSEC-2026-845

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Matrix Synapse before 0.33.3.1 and 0.33.2.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.

Ready to move

Start Securing

Free, no credit card | First findings in minutes