Technology · PyPI
matrix-synapse (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 44 vulnerabilities in matrix-synapse (PyPI): 0 in the last 7 days and 12 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2019-11842, was published on 9 July 2026.
- Last 7 days
- 0
- Last 90 days
- 12
- Critical, all time
- 0
- Exploited in the wild
- 0
About matrix-synapse (PyPI)
A reference implementation of a homeserver for the Matrix communication protocol.
Latest matrix-synapse (PyPI) vulnerabilities
- CVE-2019-11842: PYSEC-2026-2620 - matrix-sydent and matrix-synapse Use Cryptographically Weak PRNGlowCVSS 3EPSS 1.8%
- CVE-2025-61672: PYSEC-2026-1612 - Synapse's invalid device keys degrade federation functionalitymediumCVSS 4EPSS 0.5%
- CVE-2025-30355: PYSEC-2026-1614 - Synapse vulnerable to federation denial of service via malformed eventslowCVSS 3.1EPSS 1.2%
- CVE-2024-53867: PYSEC-2026-1610 - Synapse Matrix has a partial room state leak via Sliding SynclowCVSS 3.1EPSS 0.4%
- CVE-2024-53863: PYSEC-2026-1615 - Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy…mediumCVSS 4EPSS 0.6%
- CVE-2024-52815: PYSEC-2026-1611 - Synapse allows a a malformed invite to break the invitee's `/sync`mediumCVSS 4EPSS 0.6%
- CVE-2024-52805: PYSEC-2026-1613 - Synapse allows unsupported content types to lead to memory exhaustionmediumCVSS 4EPSS 0.7%
- CVE-2018-10657: PYSEC-2026-846 - Matrix Synapse DoSlowCVSS 3EPSS 1.5%
- CVE-2018-16515: PYSEC-2026-845 - Matrix Synapse Improper Signature ValidationlowCVSS 3EPSS 1.5%
- CVE-2018-12423: PYSEC-2026-844 - Matrix Synapse Authorization ErrorlowCVSS 3EPSS 1.8%
- CVE-2018-12291: PYSEC-2026-664 - Matrix Synapse Security Filtering FlawlowCVSS 3EPSS 1.8%
- CVE-2022-41952: PYSEC-2026-663 - Uncontrolled Resource Consumption in Matrix SynapselowCVSS 3.1EPSS 0.9%
- CVE-2026-45078: Element Synapse CPU starvation denial of servicemediumCVSS 5.5EPSS 0.1%
- CVE-2026-45076: Matrix Synapse denial of service in room history paginationmediumCVSS 4EPSS 0.4%
- CVE-2024-37303: Matrix Synapse unauthenticated media write in media repositorymediumCVSS 5.3EPSS 0.4%
- CVE-2024-37302: Element Synapse denial of service via media disk space consumptionhighCVSS 7.5EPSS 0.6%
- CVE-2024-31208: PYSEC-2024-50 - Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room…lowCVSS 3.1EPSS 1.5%
- CVE-2023-43796: PYSEC-2023-230 - Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device…lowCVSS 3.1EPSS 0.9%
- CVE-2023-45129: PYSEC-2023-199 - Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to…lowCVSS 3.1EPSS 1.2%
- CVE-2023-41335: PYSEC-2023-185 - Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When…lowCVSS 3.1EPSS 0.4%
- CVE-2023-42453: PYSEC-2023-180 - Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users…lowCVSS 3.1EPSS 0.7%
- CVE-2023-32682: PYSEC-2023-84 - Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. In affected versions…lowCVSS 3.1EPSS 0.8%
- CVE-2023-32683: PYSEC-2023-85 - Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed…lowCVSS 3.1EPSS 0.6%
- CVE-2022-39335: PYSEC-2023-65 - Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The…lowCVSS 3.1EPSS 0.6%
- CVE-2022-39374: PYSEC-2023-66 - Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If…lowCVSS 3.1EPSS 0.9%
Most severe matrix-synapse (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2024-37302: Element Synapse denial of service via media disk space consumptionhighCVSS 7.5EPSS 0.6%
- CVE-2026-45078: Element Synapse CPU starvation denial of servicemediumCVSS 5.5EPSS 0.1%
- CVE-2024-37303: Matrix Synapse unauthenticated media write in media repositorymediumCVSS 5.3EPSS 0.4%
- CVE-2024-52805: PYSEC-2026-1613 - Synapse allows unsupported content types to lead to memory exhaustionmediumCVSS 4EPSS 0.7%
- CVE-2024-53863: PYSEC-2026-1615 - Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy…mediumCVSS 4EPSS 0.6%
- CVE-2024-52815: PYSEC-2026-1611 - Synapse allows a a malformed invite to break the invitee's `/sync`mediumCVSS 4EPSS 0.6%
- CVE-2025-61672: PYSEC-2026-1612 - Synapse's invalid device keys degrade federation functionalitymediumCVSS 4EPSS 0.5%
- CVE-2026-45076: Matrix Synapse denial of service in room history paginationmediumCVSS 4EPSS 0.4%
- CVE-2020-26890: PYSEC-2020-237 - Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in…lowCVSS 3.1EPSS 3.0%
- CVE-2020-26257: PYSEC-2020-236 - Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver"…lowCVSS 3.1EPSS 2.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 2 | 0 | |
| 6 Jul 2026 | 10 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/matrix-synapse.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "matrix-synapse (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/matrix-synapse, 26 September 2026.