Skip to main content

Vendor/product archive

matrix / synapse CVEs

Beta · best-effort

40 CVEs tagged to matrix / synapse1 Critical, 13 High, 19 Medium, 7 Low, 0 Unrated.

CVE-2021-21394

Published Apr 12, 2021

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before v…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21333

Published Mar 26, 2021

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before v…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21332

Published Mar 26, 2021

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before v…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21273

Published Feb 26, 2021

Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before v…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-26890

Published Nov 24, 2020

Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing remote attackers to execute a de…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26891

Published Oct 19, 2020

AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsafe interpolation of the session GET parameter. This allows a remote attacker to execute an XSS atta…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-18835

Published Nov 8, 2019

Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not co…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-11842

Published May 9, 2019

An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5885

Published Mar 21, 2019

Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could all…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16515

Published Sep 18, 2018

Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validatio…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12423

Published Jun 14, 2018

In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12291

Published Jun 13, 2018

The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rul…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10657

Published May 2, 2018

Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_bas…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 26-40 of 40 CVEsPage 2 of 2