Matrix
Matrix Synapse: vulnerabilidades y CVE
Matrix Synapse tiene 40 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE40
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-30355 | Alta (7.5) | 1.2% | — | 27 mar 2025 | Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been… |
| CVE-2024-53863 | Alta (8.2) | 0.61% | — | 3 dic 2024 | Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option or processing a specially crafted request could trigger the decoding and thumbnail generation of… |
| CVE-2024-52815 | Alta (8.7) | 0.57% | — | 3 dic 2024 | Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite… |
| CVE-2024-52805 | Alta (8.2) | 0.74% | — | 3 dic 2024 | Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the… |
| CVE-2024-37303 | Media (5.3) | 0.43% | — | 3 dic 2024 | Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media from a remote homeserver to the local… |
| CVE-2024-37302 | Alta (7.5) | 0.60% | — | 3 dic 2024 | Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where an unauthenticated adversary can induce Synapse to download and cache large amounts of remote media.… |
| CVE-2024-31208 | Media (6.5) | 1.5% | — | 23 abr 2024 | Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in the V2 state… |
| CVE-2023-43796 | Media (5.3) | 0.90% | — | 31 oct 2023 | Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a… |
| CVE-2023-45129 | Media (4.9) | 1.2% | — | 10 oct 2023 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading to a… |
| CVE-2023-42453 | Media (4.3) | 0.78% | — | 27 sept 2023 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users were able to forge read receipts for any event (if they knew the room ID and event ID). Note that the users were not… |
| CVE-2023-41335 | Baja (3.7) | 0.39% | — | 27 sept 2023 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their passwords, the new credentials may be briefly held in the server database. While this doesn't… |
| CVE-2023-32683 | Media (5.4) | 0.60% | — | 6 jun 2023 | Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL can bypass the `url_preview_url_blacklist` setting potentially allowing server side request forgery… |
| CVE-2023-32682 | Media (5.4) | 0.75% | — | 6 jun 2023 | Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. In affected versions it may be possible for a deactivated user to login when using uncommon configurations. This only applies if any… |
| CVE-2023-32323 | Media (4.3) | 0.98% | — | 26 may 2023 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. A malicious user on a Synapse homeserver X with permission to create certain state events can disable outbound federation… |
| CVE-2022-39374 | Media (6.5) | 0.94% | — | 26 may 2023 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into… |
| CVE-2022-39335 | Media (5) | 0.64% | — | 26 may 2023 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix Federation API allows remote homeservers to request the authorization events in a room. This is necessary so… |
| CVE-2022-41952 | Media (5.3) | 0.91% | — | 22 nov 2022 | Synapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs without properly limiting connection time. Connections will only be terminated after… |
| CVE-2022-31152 | Alta (7.5) | 1.2% | — | 2 sept 2022 | Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specification specifies a list of [event authorization… |
| CVE-2022-31052 | Media (6.5) | 1.7% | — | 28 jun 2022 | Synapse is an open source home server implementation for the Matrix chat network. In versions prior to 1.61.1 URL previews of some web pages can exhaust the available stack space for the Synapse process due to unbounded… |
| CVE-2021-41281 | Alta (7.5) | 1.6% | — | 23 nov 2021 | Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled can be tricked into downloading a file from a remote server into an… |
| CVE-2021-39164 | Baja (3.1) | 1.5% | — | 31 ago 2021 | Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the membership (list of members, with their display names) of a room if they… |
| CVE-2021-39163 | Baja (3.1) | 0.90% | — | 31 ago 2021 | Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorised users can access the name, avatar, topic and number of members of a room if they know the ID of… |
| CVE-2021-29471 | Media (5.3) | 1.6% | — | 11 may 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.33.2 "Push rules" can specify… |
| CVE-2021-21393 | Media (6.5) | 1.6% | — | 12 abr 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input… |
| CVE-2021-21392 | Media (6.3) | 0.94% | — | 12 abr 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 requests to user provided… |
| CVE-2021-21394 | Media (6.5) | 1.5% | — | 12 abr 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input… |
| CVE-2021-21333 | Media (6.1) | 1.4% | — | 26 mar 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the notification emails… |
| CVE-2021-21332 | Alta (8.2) | 1.2% | — | 26 mar 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the password reset… |
| CVE-2021-21274 | Media (6.5) | 2.2% | — | 26 feb 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, a malicious homeserver… |
| CVE-2021-21273 | Media (6.1) | 1.8% | — | 26 feb 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, requests to user provided… |