{"schema_version":1,"title":"matrix-synapse (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 44 vulnerabilities in matrix-synapse (PyPI): 0 in the last 7 days and 12 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2019-11842, was published on 9 July 2026.","url":"https://junglewise.ai/threats/technologies/matrix-synapse","json_url":"https://junglewise.ai/threats/technologies/matrix-synapse.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/matrix-synapse","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":44,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":12,"last_365_days":14},"latest":[{"cve":"CVE-2019-11842","cvss":3,"epss":0.018,"slug":"cve-2019-11842-matrix-sydent-and-matrix-synapse-use-cryptographically-weak-prng","title":"PYSEC-2026-2620 - matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG","severity":"low","exploited":false,"published_at":"2026-07-09T16:49:47.132995+00:00","url":"https://junglewise.ai/threats/cve-2019-11842-matrix-sydent-and-matrix-synapse-use-cryptographically-weak-prng"},{"cve":"CVE-2025-61672","cvss":4,"epss":0.0047,"slug":"cve-2025-61672-synapse-s-invalid-device-keys-degrade-federation-functionality","title":"PYSEC-2026-1612 - Synapse's invalid device keys degrade federation functionality","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:07.105115+00:00","url":"https://junglewise.ai/threats/cve-2025-61672-synapse-s-invalid-device-keys-degrade-federation-functionality"},{"cve":"CVE-2025-30355","cvss":3.1,"epss":0.0118,"slug":"cve-2025-30355-synapse-vulnerable-to-federation-denial-of-service-via-malformed","title":"PYSEC-2026-1614 - Synapse vulnerable to federation denial of service via malformed events","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:59.084265+00:00","url":"https://junglewise.ai/threats/cve-2025-30355-synapse-vulnerable-to-federation-denial-of-service-via-malformed"},{"cve":"CVE-2024-53867","cvss":3.1,"epss":0.0044,"slug":"cve-2024-53867-synapse-matrix-has-a-partial-room-state-leak-via-sliding-sync","title":"PYSEC-2026-1610 - Synapse Matrix has a partial room state leak via Sliding Sync","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:46.676923+00:00","url":"https://junglewise.ai/threats/cve-2024-53867-synapse-matrix-has-a-partial-room-state-leak-via-sliding-sync"},{"cve":"CVE-2024-53863","cvss":4,"epss":0.0061,"slug":"cve-2024-53863-synapse-can-be-forced-to-thumbnail-unexpected-file-formats","title":"PYSEC-2026-1615 - Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders","severity":"medium","exploited":false,"published_at":"2026-07-07T14:34:46.538614+00:00","url":"https://junglewise.ai/threats/cve-2024-53863-synapse-can-be-forced-to-thumbnail-unexpected-file-formats"},{"cve":"CVE-2024-52815","cvss":4,"epss":0.0057,"slug":"cve-2024-52815-synapse-allows-a-a-malformed-invite-to-break-the-invitee-s-sync","title":"PYSEC-2026-1611 - Synapse allows a a malformed invite to break the invitee's `/sync`","severity":"medium","exploited":false,"published_at":"2026-07-07T14:34:46.39089+00:00","url":"https://junglewise.ai/threats/cve-2024-52815-synapse-allows-a-a-malformed-invite-to-break-the-invitee-s-sync"},{"cve":"CVE-2024-52805","cvss":4,"epss":0.0074,"slug":"cve-2024-52805-synapse-allows-unsupported-content-types-to-lead-to-memory","title":"PYSEC-2026-1613 - Synapse allows unsupported content types to lead to memory exhaustion","severity":"medium","exploited":false,"published_at":"2026-07-07T14:34:46.252699+00:00","url":"https://junglewise.ai/threats/cve-2024-52805-synapse-allows-unsupported-content-types-to-lead-to-memory"},{"cve":"CVE-2018-10657","cvss":3,"epss":0.0152,"slug":"cve-2018-10657-matrix-synapse-dos","title":"PYSEC-2026-846 - Matrix Synapse DoS","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:24.087354+00:00","url":"https://junglewise.ai/threats/cve-2018-10657-matrix-synapse-dos"},{"cve":"CVE-2018-16515","cvss":3,"epss":0.0154,"slug":"cve-2018-16515-matrix-synapse-improper-signature-validation","title":"PYSEC-2026-845 - Matrix Synapse Improper Signature Validation","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:21.195845+00:00","url":"https://junglewise.ai/threats/cve-2018-16515-matrix-synapse-improper-signature-validation"},{"cve":"CVE-2018-12423","cvss":3,"epss":0.0184,"slug":"cve-2018-12423-matrix-synapse-authorization-error","title":"PYSEC-2026-844 - Matrix Synapse Authorization Error","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:21.08032+00:00","url":"https://junglewise.ai/threats/cve-2018-12423-matrix-synapse-authorization-error"},{"cve":"CVE-2018-12291","cvss":3,"epss":0.0182,"slug":"cve-2018-12291-matrix-synapse-security-filtering-flaw","title":"PYSEC-2026-664 - Matrix Synapse Security Filtering Flaw","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:24.881978+00:00","url":"https://junglewise.ai/threats/cve-2018-12291-matrix-synapse-security-filtering-flaw"},{"cve":"CVE-2022-41952","cvss":3.1,"epss":0.0091,"slug":"cve-2022-41952-uncontrolled-resource-consumption-in-matrix-synapse","title":"PYSEC-2026-663 - Uncontrolled Resource Consumption in Matrix Synapse","severity":"low","exploited":false,"published_at":"2026-07-02T14:13:17.409521+00:00","url":"https://junglewise.ai/threats/cve-2022-41952-uncontrolled-resource-consumption-in-matrix-synapse"},{"cve":"CVE-2026-45078","cvss":5.5,"epss":0.0013,"slug":"cve-2026-45078-element-synapse-cpu-starvation-denial-of-service","title":"Element Synapse CPU starvation denial of service","severity":"medium","exploited":false,"published_at":"2026-05-28T17:16:31.75+00:00","url":"https://junglewise.ai/threats/cve-2026-45078-element-synapse-cpu-starvation-denial-of-service"},{"cve":"CVE-2026-45076","cvss":4,"epss":0.0039,"slug":"cve-2026-45076-matrix-synapse-denial-of-service-in-room-history-pagination","title":"Matrix Synapse denial of service in room history pagination","severity":"medium","exploited":false,"published_at":"2026-05-28T17:16:31.59+00:00","url":"https://junglewise.ai/threats/cve-2026-45076-matrix-synapse-denial-of-service-in-room-history-pagination"},{"cve":"CVE-2024-37303","cvss":5.3,"epss":0.0043,"slug":"cve-2024-37303-matrix-synapse-unauthenticated-media-write-in-media-repository","title":"Matrix Synapse unauthenticated media write in media repository","severity":"medium","exploited":false,"published_at":"2024-12-03T18:40:01+00:00","url":"https://junglewise.ai/threats/cve-2024-37303-matrix-synapse-unauthenticated-media-write-in-media-repository"},{"cve":"CVE-2024-37302","cvss":7.5,"epss":0.006,"slug":"cve-2024-37302-element-synapse-denial-of-service-via-media-disk-space","title":"Element Synapse denial of service via media disk space consumption","severity":"high","exploited":false,"published_at":"2024-12-03T18:39:12+00:00","url":"https://junglewise.ai/threats/cve-2024-37302-element-synapse-denial-of-service-via-media-disk-space"},{"cve":"CVE-2024-31208","cvss":3.1,"epss":0.0146,"slug":"cve-2024-31208-element-synapse-denial-of-service-via-auth-chain-indexing","title":"PYSEC-2024-50 - Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.","severity":"low","exploited":false,"published_at":"2024-04-23T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-31208-element-synapse-denial-of-service-via-auth-chain-indexing"},{"cve":"CVE-2023-43796","cvss":3.1,"epss":0.009,"slug":"cve-2023-43796-synapse-vulnerable-to-leak-of-remote-user-device-information","title":"PYSEC-2023-230 - Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried","severity":"low","exploited":false,"published_at":"2023-10-31T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-43796-synapse-vulnerable-to-leak-of-remote-user-device-information"},{"cve":"CVE-2023-45129","cvss":3.1,"epss":0.0117,"slug":"cve-2023-45129-matrix-synapse-vulnerable-to-denial-of-service-due-to-malicious","title":"PYSEC-2023-199 - Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server","severity":"low","exploited":false,"published_at":"2023-10-10T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-45129-matrix-synapse-vulnerable-to-denial-of-service-due-to-malicious"},{"cve":"CVE-2023-41335","cvss":3.1,"epss":0.0036,"slug":"cve-2023-41335-matrix-synapse-vulnerable-to-temporary-storage-of-plaintext","title":"PYSEC-2023-185 - Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their passwords, the new","severity":"low","exploited":false,"published_at":"2023-09-27T15:19:00+00:00","url":"https://junglewise.ai/threats/cve-2023-41335-matrix-synapse-vulnerable-to-temporary-storage-of-plaintext"},{"cve":"CVE-2023-42453","cvss":3.1,"epss":0.0065,"slug":"cve-2023-42453-matrix-synapse-vulnerable-to-improper-validation-of-receipts","title":"PYSEC-2023-180 - Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users were able to forge read receipts for","severity":"low","exploited":false,"published_at":"2023-09-27T15:19:00+00:00","url":"https://junglewise.ai/threats/cve-2023-42453-matrix-synapse-vulnerable-to-improper-validation-of-receipts"},{"cve":"CVE-2023-32682","cvss":3.1,"epss":0.0075,"slug":"cve-2023-32682-matrix-synapse-improper-deactivated-user-checks-during-login","title":"PYSEC-2023-84 - Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. In affected versions it may be possible for a deactiva","severity":"low","exploited":false,"published_at":"2023-06-06T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-32682-matrix-synapse-improper-deactivated-user-checks-during-login"},{"cve":"CVE-2023-32683","cvss":3.1,"epss":0.0061,"slug":"cve-2023-32683-synapse-has-url-deny-list-bypass-via-oembed-and-image-urls-when","title":"PYSEC-2023-85 - Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL can bypass the `url_p","severity":"low","exploited":false,"published_at":"2023-06-06T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-32683-synapse-has-url-deny-list-bypass-via-oembed-and-image-urls-when"},{"cve":"CVE-2022-39335","cvss":3.1,"epss":0.0064,"slug":"cve-2022-39335-synapse-does-not-apply-enough-checks-to-servers-requesting-auth","title":"PYSEC-2023-65 - Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix Federation API allows remote hom","severity":"low","exploited":false,"published_at":"2023-05-26T14:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-39335-synapse-does-not-apply-enough-checks-to-servers-requesting-auth"},{"cve":"CVE-2022-39374","cvss":3.1,"epss":0.0094,"slug":"cve-2022-39374-synapse-denial-of-service-due-to-incorrect-application-of-event","title":"PYSEC-2023-66 - Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are b","severity":"low","exploited":false,"published_at":"2023-05-26T14:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-39374-synapse-denial-of-service-due-to-incorrect-application-of-event"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":10},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"matrix-synapse (PyPI)","slug":"matrix-synapse","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://pypi.org/project/matrix-synapse/","repo_url":"https://github.com/element-hq/synapse","description":"A reference implementation of a homeserver for the Matrix communication protocol.","url":"https://junglewise.ai/threats/technologies/matrix-synapse"},"most_severe":[{"cve":"CVE-2024-37302","cvss":7.5,"epss":0.006,"slug":"cve-2024-37302-element-synapse-denial-of-service-via-media-disk-space","title":"Element Synapse denial of service via media disk space consumption","severity":"high","exploited":false,"published_at":"2024-12-03T18:39:12+00:00","url":"https://junglewise.ai/threats/cve-2024-37302-element-synapse-denial-of-service-via-media-disk-space"},{"cve":"CVE-2026-45078","cvss":5.5,"epss":0.0013,"slug":"cve-2026-45078-element-synapse-cpu-starvation-denial-of-service","title":"Element Synapse CPU starvation denial of service","severity":"medium","exploited":false,"published_at":"2026-05-28T17:16:31.75+00:00","url":"https://junglewise.ai/threats/cve-2026-45078-element-synapse-cpu-starvation-denial-of-service"},{"cve":"CVE-2024-37303","cvss":5.3,"epss":0.0043,"slug":"cve-2024-37303-matrix-synapse-unauthenticated-media-write-in-media-repository","title":"Matrix Synapse unauthenticated media write in media repository","severity":"medium","exploited":false,"published_at":"2024-12-03T18:40:01+00:00","url":"https://junglewise.ai/threats/cve-2024-37303-matrix-synapse-unauthenticated-media-write-in-media-repository"},{"cve":"CVE-2024-52805","cvss":4,"epss":0.0074,"slug":"cve-2024-52805-synapse-allows-unsupported-content-types-to-lead-to-memory","title":"PYSEC-2026-1613 - Synapse allows unsupported content types to lead to memory exhaustion","severity":"medium","exploited":false,"published_at":"2026-07-07T14:34:46.252699+00:00","url":"https://junglewise.ai/threats/cve-2024-52805-synapse-allows-unsupported-content-types-to-lead-to-memory"},{"cve":"CVE-2024-53863","cvss":4,"epss":0.0061,"slug":"cve-2024-53863-synapse-can-be-forced-to-thumbnail-unexpected-file-formats","title":"PYSEC-2026-1615 - Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders","severity":"medium","exploited":false,"published_at":"2026-07-07T14:34:46.538614+00:00","url":"https://junglewise.ai/threats/cve-2024-53863-synapse-can-be-forced-to-thumbnail-unexpected-file-formats"},{"cve":"CVE-2024-52815","cvss":4,"epss":0.0057,"slug":"cve-2024-52815-synapse-allows-a-a-malformed-invite-to-break-the-invitee-s-sync","title":"PYSEC-2026-1611 - Synapse allows a a malformed invite to break the invitee's `/sync`","severity":"medium","exploited":false,"published_at":"2026-07-07T14:34:46.39089+00:00","url":"https://junglewise.ai/threats/cve-2024-52815-synapse-allows-a-a-malformed-invite-to-break-the-invitee-s-sync"},{"cve":"CVE-2025-61672","cvss":4,"epss":0.0047,"slug":"cve-2025-61672-synapse-s-invalid-device-keys-degrade-federation-functionality","title":"PYSEC-2026-1612 - Synapse's invalid device keys degrade federation functionality","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:07.105115+00:00","url":"https://junglewise.ai/threats/cve-2025-61672-synapse-s-invalid-device-keys-degrade-federation-functionality"},{"cve":"CVE-2026-45076","cvss":4,"epss":0.0039,"slug":"cve-2026-45076-matrix-synapse-denial-of-service-in-room-history-pagination","title":"Matrix Synapse denial of service in room history pagination","severity":"medium","exploited":false,"published_at":"2026-05-28T17:16:31.59+00:00","url":"https://junglewise.ai/threats/cve-2026-45076-matrix-synapse-denial-of-service-in-room-history-pagination"},{"cve":"CVE-2020-26890","cvss":3.1,"epss":0.03,"slug":"cve-2020-26890-denial-of-service-attack-due-to-invalid-json","title":"PYSEC-2020-237 - Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, al","severity":"low","exploited":false,"published_at":"2020-11-24T03:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-26890-denial-of-service-attack-due-to-invalid-json"},{"cve":"CVE-2020-26257","cvss":3.1,"epss":0.0239,"slug":"cve-2020-26257-denial-of-service-attack-via-incorrect-parameters-in-matrix","title":"PYSEC-2020-236 - Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference \"homeserver\" implementation of Matrix. A malici","severity":"low","exploited":false,"published_at":"2020-12-09T19:15:00+00:00","url":"https://junglewise.ai/threats/cve-2020-26257-denial-of-service-attack-via-incorrect-parameters-in-matrix"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}