Syncthing is a decentralized file synchronization tool that enables peer-to-peer data replication across devices, presenting a focused attack surface centered on its core synchronization protocol and web interface. Its observed vulnerability patterns cluster around input validation, link-following issues in file handling, and web-interface cross-site scripting, reflecting the risks inherent to parsing untrusted sync messages and managing web-based configuration. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Syncthing over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21404HIGH Syncthing is a continuous file synchronization program. In Syncthing before version 1.15.0, the relay server `strelaysrv` can be caused to crash and exit by sending a relay message | Apr 6, 2021 | 7.5 | 25 | NO | NO |
CVE-2017-1000420HIGH Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite | Jan 2, 2018 | 7.5 | 25 | NO | NO |
CVE-2022-46165MEDIUM Syncthing is an open source, continuous file synchronization program. In versions prior to 1.23.5 a compromised instance with shared folders could sync malicious files which contai | Jun 6, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Syncthing.
Media articles that mention a CVE ID that affects a product developed by Syncthing — matched by CVE ID, not by vendor name.