CVE-2024-53867: Element-Hq Synapse
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Synapse is an open-source Matrix homeserver. The Sliding Sync feature on Synapse versions between 1.113.0rc1 and 1.120.0 can leak partial room state changes to users no longer in a room. Non-state events, like messages, are unaffected. This vulnerability is fixed in 1.120.1.
Affected products
- Element-Hq Synapse: from 1.113.0rc1, before 1.120.1 (fixed in 1.120.1)
Published 2024-12-03. Last modified 2026-06-17.