Where
-Infinity
0

synapse SynapseSynapse vulnerable to federation denial of service via malformed events

Risk 31
Severity
7.5
EPSS
0.38%
First published (updated )

Fedoraproject FedoraSynapse vulnerable to leak of remote user device information

Risk 28
Severity
5.3
First published (updated )

Fedoraproject Fedoramatrix-synapse vulnerable to denial of service due to malicious server ACL events

Risk 31
Severity
4.9
First published (updated )

Fedoraproject FedoraImproper validation of receipts allows forged read receipts in matrix synapse

Risk 23
Severity
4.3
First published (updated )

Fedoraproject FedoraTemporary storage of plaintext passwords during password changes in matrix synapse

Risk 24
Severity
3.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

matrix synapseURL deny list bypass via oEmbed and image URLs when generating previews in Synapse

Risk 36
Severity
5.4
First published (updated )

matrix synapseImproper checks for deactivated users during login in synapse

Risk 36
Severity
5.4
First published (updated )

matrix synapseSynapse Outgoing federation to specific hosts can be disabled by sending malicious invites

Risk 26
Severity
5
First published (updated )

matrix synapseSynapse Denial of service due to incorrect application of event authorization rules during state resolution

Risk 40
Severity
6.5
First published (updated )

matrix synapseSynapse does not apply enough checks to servers requesting auth events of events in a room

Risk 41
Severity
5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

matrix synapseUncontrolled Resource Consumption in Matrix Synapse

Risk 40
Severity
6.5
First published (updated )

matrix synapseSynapse vulnerable to denial of service (DoS) due to incorrect application of event authorization rules

Risk 45
Severity
7.5
First published (updated )

Fedoraproject FedoraURL previews can crash Synapse media repositories or Synapse monoliths

Risk 40
Severity
6.5
First published (updated )

Fedoraproject FedoraPath traversal in Matrix Synapse

Risk 45
Severity
7.5
First published (updated )

Fedoraproject FedoraImproper authorisation of /members discloses room membership to non-members

Risk 19
Severity
3.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Fedoraproject FedoraAdding a private/unlisted room to a community exposes room metadata in an unauthorised manner.

Risk 19
Severity
3.5
First published (updated )

pip/matrix-synapseDenial of service in Matrix Synapse

Risk 28
Severity
5.3
First published (updated )

pip/matrix-synapseOpen redirect via transitional IPv6 addresses on dual-stack networks

Risk 45
Severity
6.3
First published (updated )

pip/matrix-synapseDenial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints

Risk 40
Severity
6.5
First published (updated )

pip/matrix-synapseDenial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints

Risk 40
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/matrix-synapseHTML injection in email and account expiry notifications

Risk 37
Severity
6.1
First published (updated )

pip/matrix-synapseCross-site scripting (XSS) vulnerability in the password reset endpoint

Risk 56
Severity
8.2
First published (updated )

pip/matrix-synapseOpen redirects on some federation and push requests

Risk 39
Severity
6.1
First published (updated )

pip/matrix-synapseDenial of service attack via .well-known lookups

Risk 39
Severity
6.5
First published (updated )

Fedoraproject FedoraDenial of service attack via incorrect parameters to federation APIs

Risk 40
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Fedoraproject FedoraInput Validation

Risk 45
Severity
7.5
First published (updated )

matrix synapseXSS, CSRF

Risk 39
Severity
6.1
First published (updated )

matrix synapseMatrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over …

Risk 89
Severity
9.8
First published (updated )

matrix SydentWeak RNG

Risk 45
Severity
7.5
First published (updated )

Fedoraproject FedoraMatrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, us…

Risk 45
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203