Search CVE reports


Toggle filters

1 – 10 of 44 results


CVE-2026-45078

Medium priority
Needs evaluation

Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied...

1 affected package

matrix-synapse

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matrix-synapse Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-45076

Medium priority
Needs evaluation

Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full history to paginating clients....

1 affected package

matrix-synapse

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matrix-synapse Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-61672

Medium priority
Needs evaluation

Synapse is an open source Matrix homeserver implementation. Lack of validation for device keys in Synapse before 1.138.3 and in Synapse 1.139.0 allow an attacker registered on the victim homeserver to degrade...

1 affected package

matrix-synapse

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matrix-synapse Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-30355

Medium priority
Needs evaluation

Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited...

1 affected package

matrix-synapse

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matrix-synapse Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-53867

Medium priority
Not affected

Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room. Non-state events, like messages,...

1 affected package

matrix-synapse

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matrix-synapse Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-53863

Medium priority

Some fixes available 1 of 3

Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option or processing a specially crafted request could trigger the decoding and thumbnail generation of uncommon...

1 affected package

matrix-synapse

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matrix-synapse Ignored Fixed Not affected Not affected
Show less packages

CVE-2024-52815

Medium priority
Vulnerable

Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts...

1 affected package

matrix-synapse

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matrix-synapse Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2024-52805

Medium priority
Vulnerable

Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which...

1 affected package

matrix-synapse

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matrix-synapse Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2024-37303

Medium priority
Vulnerable

Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media from a remote homeserver to the local media...

1 affected package

matrix-synapse

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matrix-synapse Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2024-37302

Medium priority
Vulnerable

Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where an unauthenticated adversary can induce Synapse to download and cache large amounts of remote media....

1 affected package

matrix-synapse

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
matrix-synapse Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages