matrix-synapse is vulnerable to Denial of Service (DoS)
50
Medium Risk
When a joined room contains an invalid name or avatar, or users with invalid profile data, Synapse can produce an invalid MSC4186 Sliding Sync response. Clients such as Element X fail to process the malformed response and cannot make forward progress. This renders the application unusable for the affected end-user. The fix ensures Synapse produces valid Sliding Sync responses even when room or profile data is invalid.
You are affected if you are using a version that falls within the vulnerable range and your homeserver federates or has untrusted local users.
matrix-synapse is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 1.157.1.
Upgrade the matrix-synapse library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant