matrix-synapse vulnerabilities

Homeserver for the Matrix decentralised comms protocol

  • latest version

    1.138.0

  • latest non vulnerable version

  • first published

    6 years ago

  • latest version published

    7 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the matrix-synapse package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Improper Input Validation

    [,1.127.1)
    • H
    Improper Input Validation

    [,1.120.2)
    • H
    Allocation of Resources Without Limits or Throttling

    [,1.106.0)
    • M
    Missing Authentication for Critical Function

    [,1.106.0)
    • M
    Exposure of Sensitive System Information to an Unauthorized Control Sphere

    [1.113.0rc1,1.120.2)
    • H
    Arbitrary File Upload

    [,1.120.2)
    • H
    Allocation of Resources Without Limits or Throttling

    [,1.120.2)
    • M
    Allocation of Resources Without Limits or Throttling

    [,1.105.1)
    • M
    Information Exposure

    [,1.95.1)
    • M
    Allocation of Resources Without Limits or Throttling

    [,1.94.0rc1)
    • M
    Improper Input Validation

    [0.34.0,1.93.0)
    • M
    Information Exposure

    [1.66.0,1.93.0)
    • H
    Denial of Service (DoS)

    [,0.34.0)
    • M
    Incorrect Authorization

    [,1.85.0rc1)
    • L
    Server-side Request Forgery (SSRF)

    [,1.85.0rc1)
    • M
    Denial of Service (DoS)

    [,1.74.0rc1)
    • M
    Denial of Service (DoS)

    [1.62.0,1.68.0rc1)
    • L
    Access Restriction Bypass

    [,1.69.0rc1)
    • M
    Allocation of Resources Without Limits or Throttling

    [,1.53.0)
    • M
    Denial of Service (DoS)

    [,1.62.0)
    • M
    Uncontrolled Recursion

    [,1.61.1)
    • H
    Directory Traversal

    [,1.47.1)
    • M
    Information Exposure

    [,1.41.1)
    • L
    Information Exposure

    [,1.41.1)
    • H
    Insufficiently Protected Credentials

    [,0.34.0.1)
    • M
    Insecure Randomness

    [,0.99.3.1)
    • H
    Denial of Service (DoS)

    [,1.33.0)
    • L
    Denial of Service (DoS)

    [,1.33.2)
    • M
    Denial of Service (DoS)

    [,1.28.0)
    • M
    Open Redirect

    [,1.28.0)
    • M
    Denial of Service (DoS)

    [,1.28.0)
    • H
    Cross-site Scripting (XSS)

    [,1.27.0)
    • M
    Improper Input Validation

    [,1.27.0)
    • L
    Insecure Defaults

    [,1.25.0)
    • M
    Denial of Service (DoS)

    [0.99.0,1.25.0rc1)
    • M
    Denial of Service (DoS)

    [,1.23.1)
    • H
    Denial of Service (DoS)

    [,1.20.0)
    • M
    Cross-site Scripting (XSS)

    [,1.21.0)
    • H
    Insufficient Verification of Data Authenticity

    [,1.5.0rc2)

    Package versions

    460 VERSIONS IN TOTAL See all versions
    versionpublisheddirect vulnerabilities
    1.138.09 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    1.138.0rc12 Sep, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    1.137.026 Aug, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    1.137.0rc119 Aug, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    1.136.012 Aug, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    1.136.0rc211 Aug, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    1.136.0rc17 Aug, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    1.135.211 Aug, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    1.135.01 Aug, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L
    1.135.0rc230 Jul, 2025
    • 0
      C
    • 0
      H
    • 0
      M
    • 0
      L