Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-1612
  • PyPI/matrix-synapse
Synapse's invalid device keys degrade federation functionality 07 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-1614
  • PyPI/matrix-synapse
Synapse vulnerable to federation denial of service via malformed events 07 Jul
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-1610
  • PyPI/matrix-synapse
Synapse Matrix has a partial room state leak via Sliding Sync 07 Jul
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-1615
  • PyPI/matrix-synapse
Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders 07 Jul
  • Fix available
  • Severity - 8.2 (High)
PYSEC-2026-1611
  • PyPI/matrix-synapse
Synapse allows a a malformed invite to break the invitee's `/sync` 07 Jul
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-1613
  • PyPI/matrix-synapse
Synapse allows unsupported content types to lead to memory exhaustion 07 Jul
  • Fix available
  • Severity - 8.2 (High)
PYSEC-2026-846
  • PyPI/matrix-synapse
Matrix Synapse DoS 06 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-845
  • PyPI/matrix-synapse
Matrix Synapse Improper Signature Validation 06 Jul
  • Fix available
  • Severity - 8.8 (High)
PYSEC-2026-844
  • PyPI/matrix-synapse
Matrix Synapse Authorization Error 06 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-664
  • PyPI/matrix-synapse
Matrix Synapse Security Filtering Flaw 02 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-663
  • PyPI/matrix-synapse
Uncontrolled Resource Consumption in Matrix Synapse 02 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-191
  • PyPI/matrix-synapse
See record for full details 28 May
  • Fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-194
  • PyPI/matrix-synapse
See record for full details 28 May
  • Fix available
  • Severity - 2.7 (Low)
GHSA-6qf2-7x63-mm6v
  • PyPI/matrix-synapse
Synapse pagination Denial of Service 14 May
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-8q93-326v-3m7g
  • PyPI/matrix-synapse
Synapse CPU starvation (Denial of Service) 14 May
  • Fix available
  • Severity - 7.1 (High)
GHSA-fh66-fcv5-jjfr
  • PyPI/matrix-synapse
Synapse's invalid device keys degrade federation functionality 08 Oct 2025
  • Fix available
  • Severity - 5.3 (Medium)