matrix-synapse vulnerabilities

Homeserver for the Matrix decentralised comms protocol

  • latest version

    1.139.2

  • latest non vulnerable version

  • first published

    7 years ago

  • latest version published

    5 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the matrix-synapse package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Improper Validation of Specified Type of Input

    [,1.138.3)[1.139.0rc2,1.139.1)
    • H
    Improper Input Validation

    [,1.127.1)
    • H
    Improper Input Validation

    [,1.120.2)
    • H
    Allocation of Resources Without Limits or Throttling

    [,1.106.0)
    • M
    Missing Authentication for Critical Function

    [,1.106.0)
    • M
    Exposure of Sensitive System Information to an Unauthorized Control Sphere

    [1.113.0rc1,1.120.2)
    • H
    Arbitrary File Upload

    [,1.120.2)
    • H
    Allocation of Resources Without Limits or Throttling

    [,1.120.2)
    • M
    Allocation of Resources Without Limits or Throttling

    [,1.105.1)
    • M
    Information Exposure

    [,1.95.1)
    • M
    Allocation of Resources Without Limits or Throttling

    [,1.94.0rc1)
    • M
    Improper Input Validation

    [0.34.0,1.93.0)
    • M
    Information Exposure

    [1.66.0,1.93.0)
    • H
    Denial of Service (DoS)

    [,0.34.0)
    • M
    Incorrect Authorization

    [,1.85.0rc1)
    • L
    Server-side Request Forgery (SSRF)

    [,1.85.0rc1)
    • M
    Denial of Service (DoS)

    [,1.74.0rc1)
    • M
    Denial of Service (DoS)

    [1.62.0,1.68.0rc1)
    • L
    Access Restriction Bypass

    [,1.69.0rc1)
    • M
    Allocation of Resources Without Limits or Throttling

    [,1.53.0)
    • M
    Denial of Service (DoS)

    [,1.62.0)
    • M
    Uncontrolled Recursion

    [,1.61.1)
    • H
    Directory Traversal

    [,1.47.1)
    • M
    Information Exposure

    [,1.41.1)
    • L
    Information Exposure

    [,1.41.1)
    • H
    Insufficiently Protected Credentials

    [,0.34.0.1)
    • M
    Insecure Randomness

    [,0.99.3.1)
    • H
    Denial of Service (DoS)

    [,1.33.0)
    • L
    Denial of Service (DoS)

    [,1.33.2)
    • M
    Denial of Service (DoS)

    [,1.28.0)
    • M
    Open Redirect

    [,1.28.0)
    • M
    Denial of Service (DoS)

    [,1.28.0)
    • H
    Cross-site Scripting (XSS)

    [,1.27.0)
    • M
    Improper Input Validation

    [,1.27.0)
    • L
    Insecure Defaults

    [,1.25.0)
    • M
    Denial of Service (DoS)

    [0.99.0,1.25.0rc1)
    • M
    Denial of Service (DoS)

    [,1.23.1)
    • H
    Denial of Service (DoS)

    [,1.20.0)
    • M
    Cross-site Scripting (XSS)

    [,1.21.0)
    • H
    Insufficient Verification of Data Authenticity

    [,1.5.0rc2)

    Package versions

    469 VERSIONS IN TOTAL See all versions
    versionpublisheddirect vulnerabilities
    1.140.0rc110 Oct, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    1.139.28 Oct, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    1.139.17 Oct, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    1.139.01 Oct, 2025
    • 0
      C
    • 0
      H
    • 1
      M
    • 0
      L
    1.139.0rc325 Sep, 2025
    • 0
      C
    • 0
      H
    • 1
      M
    • 0
      L
    1.139.0rc223 Sep, 2025
    • 0
      C
    • 0
      H
    • 1
      M
    • 0
      L
    1.138.48 Oct, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    1.138.37 Oct, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    1.138.224 Sep, 2025
    • 0
      C
    • 0
      H
    • 1
      M
    • 0
      L
    1.138.09 Sep, 2025
    • 0
      C
    • 0
      H
    • 1
      M
    • 0
      L