Intel

AIKIDO-2026-857258

matrix-synapse is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-jhcg-5392-5mjw Published 4 days ago

50

Medium Risk

This Affects:

PYTHONmatrix-synapse
0.0.1 - 1.157.1
Fixed in 1.157.2
Are you affected? Scan for Free

TL;DR

When a joined room contains an invalid name or avatar, or users with invalid profile data, Synapse can produce an invalid MSC4186 Sliding Sync response. Clients such as Element X fail to process the malformed response and cannot make forward progress. This renders the application unusable for the affected end-user. The fix ensures Synapse produces valid Sliding Sync responses even when room or profile data is invalid.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your homeserver federates or has untrusted local users.

Background info

matrix-synapse is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 1.157.1.

How to fix this

Upgrade the matrix-synapse library to the patch version.