CVE-2018-10657: Matrix Synapse
High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.
Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018.
Affected products
- Matrix Synapse: before 0.28.1 (fixed in 0.28.1)
Published 2018-05-02. Last modified 2026-06-17.