CVE-2018-10657 describes a denial-of-service vulnerability affecting Matrix Synapse versions prior to 0.28.1. This flaw allows an attacker to render chat rooms unusable by injecting malicious events with an extremely large depth value. The vulnerability carries a CVSS v3 score of 7.5 (High), indicating it can be exploited remotely with low attack complexity and without user interaction, leading to a high impact on availability. This vulnerability was exploited in the wild in April 2018, though there is no publicly available exploit code, Metasploit module, or significant community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.28.1CPE matchmatch criteria | cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.