This repository was archived by the owner on Apr 26, 2024. It is now read-only.
Security: matrix-org/synapse
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
URL previews of unusual or maliciously-crafted pages can crash Synapse media repositories or Synapse monolithsGHSA-22p3-qrh9-cx32 published
Jun 28, 2022 by anoadragon453High -
Generating URL previews of media streams causing long-lived connectionsGHSA-4822-jvwx-w47h published
Mar 31, 2022 by dkasakModerate -
Path traversal when downloading remote mediaGHSA-3hfw-x7gx-437c published
Nov 23, 2021 by squahtxHigh -
Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.GHSA-jj53-8fmw-f2w2 published
Aug 31, 2021 by richvdhModerate -
Improper authorisation of /members discloses room membership to non-membersGHSA-3x4c-pq33-4w3q published
Aug 31, 2021 by richvdhModerate -
Denial of service (via resource exhaustion) due to improper input validation in third-party identifier endpointGHSA-7h5v-85w9-pq6c published
May 11, 2021 by babolivierModerate -
Denial of service attack via push rule patternsGHSA-x345-32rc-8h85 published
May 11, 2021 by richvdhModerate -
Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpointsGHSA-w9fg-xffh-p362 published
Apr 12, 2021 by richvdhLow -
Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpointsGHSA-jrh7-mhhx-6h88 published
Apr 12, 2021 by richvdhLow -
HTML injection in email and account expiry notificationsGHSA-c5f8-35qr-q4fm published
Mar 25, 2021 by clokepLow