CVE-2024-52815: Matrix Synapse

Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.

Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user's /sync functionality. Synapse 1.120.1 rejects such invalid invites received over federation and restores the ability to sync for affected users.

Affected products

  • Matrix Synapse: before 1.120.1 (fixed in 1.120.1)

Published 2024-12-03. Last modified 2026-06-17.