HIGH8.6CVE-2019-18835Improper Verification of Cryptographic Signature in matrix-synapse from 0, < 1.5.0-1
HIGH7.5CVE-2024-37302Synapse denial of service through media disk space consumption from 0, < 1.116.0-1
HIGH7.5CVE-2022-31152Denial of service due to incorrect application of event authorization rules from 0, < 1.63.0-1
HIGH7.5Matrix Synapse Predictable Secret Key
from 0, < 0.34.1.1-1
MEDIUM6.5Synapse V2 state resolution weakness allows Denial of Service (DoS)
from 0, < 1.103.0-2
MEDIUM6.5Synapse Denial of service due to incorrect application of event authorization rules during state resolution
from 0, < 1.68.0-1
MEDIUM6.5URL previews of unusual or maliciously-crafted pages can crash Synapse media repositories or Synapse monoliths
from 0, < 1.61.1-1
MEDIUM6.5Denial of service attack via incorrect parameters in Matrix Synapse
from 0, < 1.24.0-1
MEDIUM5.5Synapse CPU starvation (Denial of Service)
from 0, < 1.152.1-1
MEDIUM5.4Synapse has improper checks for deactivated users during login
from 0, < 1.90.0-1
MEDIUM5.3Synapse's unauthenticated writes to the media repository allow planting of problematic content
from 0, < 1.116.0-1
MEDIUM5.3Synapse vulnerable to leak of remote user device information
from 0, < 1.95.1-1
MEDIUM5.0Synapse Outgoing federation to specific hosts can be disabled by sending malicious invites
from 0, < 1.74.0-1
MEDIUM5.0Synapse does not apply enough checks to servers requesting auth events of events in a room
from 0, < 1.69.0-1
MEDIUM4.9matrix-synapse vulnerable to denial of service due to malicious server ACL events
from 0, < 1.94.0-1
MEDIUM4.3Denial of service attack via .well-known lookups
from 0, < 1.25.0-1
LOW3.7matrix-synapse vulnerable to temporary storage of plaintext passwords during password changes
from 0, < 1.93.0-1
LOW3.5Synapse has URL deny list bypass via oEmbed and image URLs when generating previews
from 0, < 1.90.0-1
LOW3.1matrix-synapse vulnerable to improper validation of receipts allows forged read receipts
from 0, < 1.93.0-1
LOW2.7Synapse pagination Denial of Service
from 0, < 1.152.1-1