5.1 MEDIUM
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): High (H)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): None (N)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): Low (L)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): High (H)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): None (N)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): Low (L)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
Activity log
- Created suggestion
Synapse pagination denial of service
Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full history to paginating clients. Clients could therefore fail to display room history. This vulnerability is fixed in 1.152.1.
References
-
https://github.com/element-hq/synapse/security/advisories/GHSA-6qf2-7x63-mm6v x_refsource_CONFIRM
Affected products
- ==< 1.152.1
Matching in nixpkgs
pkgs.synapse
Semantic launcher to start applications and find relevant files
pkgs.synapse-bt
Flexible and fast BitTorrent daemon
-
nixos-unstable 2023-02-16
- nixpkgs-unstable 2023-02-16
- nixos-unstable-small 2023-02-16
-
nixos-25.11 2023-02-16
- nixos-25.11-small 2023-02-16
- nixpkgs-25.11-darwin 2023-02-16
pkgs.synapse-admin
Admin UI for Synapse Homeservers
pkgs.matrix-synapse
Matrix reference homeserver
pkgs.synapse-admin-etkecc
Maintained fork of the admin console for (Matrix) Synapse homeservers, including additional features
-
nixos-25.11 0.11.4-etke54
- nixos-25.11-small 0.11.4-etke54
- nixpkgs-25.11-darwin 0.11.4-etke54
pkgs.matrix-synapse-unwrapped
Matrix reference homeserver
pkgs.rust-synapse-compress-state
Tool to compress some state in a Synapse instance's database
pkgs.python312Packages.azure-mgmt-synapse
Microsoft Azure Synapse Management Client Library
pkgs.python313Packages.azure-mgmt-synapse
Microsoft Azure Synapse Management Client Library
pkgs.python314Packages.azure-mgmt-synapse
Microsoft Azure Synapse Management Client Library
pkgs.python312Packages.azure-synapse-spark
Microsoft Azure Synapse Spark Client Library
pkgs.python313Packages.azure-synapse-spark
Microsoft Azure Synapse Spark Client Library
pkgs.python314Packages.azure-synapse-spark
Microsoft Azure Synapse Spark Client Library
pkgs.matrix-synapse-plugins.matrix-synapse-pam
PAM auth provider for the Synapse Matrix server
pkgs.python312Packages.azure-synapse-artifacts
Microsoft Azure Synapse Artifacts Client Library for Python
pkgs.python313Packages.azure-synapse-artifacts
Microsoft Azure Synapse Artifacts Client Library for Python
pkgs.python314Packages.azure-synapse-artifacts
Microsoft Azure Synapse Artifacts Client Library for Python
pkgs.matrix-synapse-plugins.matrix-synapse-ldap3
LDAP3 auth provider for Synapse
-
nixos-unstable ldap3-0.4.0
- nixpkgs-unstable ldap3-0.4.0
- nixos-unstable-small ldap3-0.4.0
-
nixos-25.11 ldap3-0.3.0
- nixos-25.11-small ldap3-0.3.0
- nixpkgs-25.11-darwin ldap3-0.3.0
pkgs.matrix-synapse-plugins.synapse-http-antispam
Synapse module that forwards spam checking to an HTTP server
pkgs.python312Packages.azure-synapse-accesscontrol
Microsoft Azure Synapse AccessControl Client Library
pkgs.python313Packages.azure-synapse-accesscontrol
Microsoft Azure Synapse AccessControl Client Library
pkgs.python314Packages.azure-synapse-accesscontrol
Microsoft Azure Synapse AccessControl Client Library
pkgs.matrix-synapse-plugins.matrix-http-rendezvous-synapse
Implementation of MSC3886: Simple rendezvous capability
pkgs.matrix-synapse-plugins.matrix-synapse-mjolnir-antispam
AntiSpam / Banlist plugin to be used with mjolnir
pkgs.python312Packages.azure-synapse-managedprivateendpoints
Microsoft Azure Synapse Managed Private Endpoints Client Library
pkgs.python313Packages.azure-synapse-managedprivateendpoints
Microsoft Azure Synapse Managed Private Endpoints Client Library
pkgs.python314Packages.azure-synapse-managedprivateendpoints
Microsoft Azure Synapse Managed Private Endpoints Client Library
pkgs.matrix-synapse-plugins.matrix-synapse-shared-secret-auth
Shared Secret Authenticator password provider module for Matrix Synapse
pkgs.matrix-synapse-plugins.matrix-synapse-s3-storage-provider
Synapse storage provider to fetch and store media in Amazon S3
-
nixos-unstable s3-storage-provider-1.6.0
- nixpkgs-unstable s3-storage-provider-1.6.1
- nixos-unstable-small s3-storage-provider-1.6.1
-
nixos-25.11 s3-storage-provider-1.6.0
- nixos-25.11-small s3-storage-provider-1.6.0
- nixpkgs-25.11-darwin s3-storage-provider-1.6.0
Package maintainers
-
@mguentner Maximilian Güntner <code@mguentner.de>
-
@NickCao Nick Cao <nickcao@nichi.co>
-
@teutat3s teutat3s <teutates@mailbox.org>
-
@D4ndellion Daniel Olsen <daniel@dodsorf.as>
-
@Ma27 Maximilian Bosch <maximilian@mbosch.me>
-
@sumnerevans Sumner Evans <me@sumnerevans.com>
-
@SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
-
@jojosch Johannes Schleifenbaum <johannes@js-webcoding.de>
-
@maralorn maralorn <mail@maralorn.de>
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>
-
@2chilled Matthias Herrmann <matthias.mh.herrmann@gmail.com>
-
@mkg20001 Maciej Krüger <mkg20001+nix@gmail.com>
-
@dywedir Vladyslav M. <dywedir@gra.red>
-
@Defelo Defelo