Synapse
Vendor:
First CVE: May 2, 2018 · Active for 8 years
40
Total CVEs
More Total CVEs than 97% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Synapse over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2018
8 years ago
Most Recent CVE
Mar 27, 2025
484 days ago
CVE Severity & Scoring
Synapse40 CVEs
55%
33%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network40 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low35 (87.5%)
High5 (12.5%)
Unknown0 (0.0%)
User Interaction
None33 (82.5%)
Unknown0 (0.0%)
Required7 (17.5%)
Privileges Required
Low16 (40.0%)
High1 (2.5%)
None23 (57.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-18835CRITICAL Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not com | Nov 8, 2019 | 9.8 | 30 | NO | NO |
CVE-2018-16515HIGH Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation | Sep 18, 2018 | 8.8 | 27 | NO | NO |
CVE-2025-30355HIGH Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with oth | Mar 27, 2025 | 7.5 | 26 | NO | NO |
CVE-2024-53863CRITICAL Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option or processing a specially crafted request could trigger the | Dec 3, 2024 | 9.1 | 25 | NO | NO |
CVE-2021-41281HIGH Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled can be tricked into downloadin | Nov 23, 2021 | 7.5 | 25 | NO | NO |
CVE-2021-21332HIGH Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before ve | Mar 26, 2021 | 8.2 | 25 | NO | NO |
CVE-2020-26890HIGH Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing remote attackers to execute a den | Nov 24, 2020 | 7.5 | 25 | NO | NO |
CVE-2019-11842HIGH An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent a | May 9, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-5885HIGH Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allo | Mar 21, 2019 | 7.5 | 25 | NO | NO |
CVE-2022-31152HIGH Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specification specifies a list of [event authorization rules](https://sp | Sep 2, 2022 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (40 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (40 CVEs).
Media Mentions
Signals from CVEs in this product scope (40 CVEs).
Top CNAs Publishing CVEs For Synapse
Top CWEs
Versions
No cataloged versions.