Synapse

Vendor:

First CVE: May 2, 2018 · Active for 8 years

40
Total CVEs
More Total CVEs than 97% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Synapse over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2018
8 years ago
Most Recent CVE
Mar 27, 2025
484 days ago

CVE Severity & Scoring

Synapse40 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network40 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low35 (87.5%)
High5 (12.5%)
Unknown0 (0.0%)
User Interaction
None33 (82.5%)
Unknown0 (0.0%)
Required7 (17.5%)
Privileges Required
Low16 (40.0%)
High1 (2.5%)
None23 (57.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (40 CVEs).

40 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not com
Nov 8, 20199.830NONO
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation
Sep 18, 20188.827NONO
Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with oth
Mar 27, 20257.526NONO
Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option or processing a specially crafted request could trigger the
Dec 3, 20249.125NONO
Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled can be tricked into downloadin
Nov 23, 20217.525NONO
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before ve
Mar 26, 20218.225NONO
Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing remote attackers to execute a den
Nov 24, 20207.525NONO
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent a
May 9, 20197.525NONO
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allo
Mar 21, 20197.525NONO
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specification specifies a list of [event authorization rules](https://sp
Sep 2, 20227.524NONO

Exploit Exposure

Signals from CVEs in this product scope (40 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (40 CVEs).

Media Mentions

Signals from CVEs in this product scope (40 CVEs).

Top CNAs Publishing CVEs For Synapse

Top CWEs

Versions

No cataloged versions.