← Back to CVE List
Vulnerability Intelligence Report
Synapse allows a a malformed invite to break the invitee's `/sync`

CVE-2024-52815

Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user's /sync functionality. Synapse 1.120.1 rejects such invalid invites received over federation and restores the ability to sync for affected users.

No Active Exploit Signals
CVSS Base Score
8.7
HIGH
EPSS Probability:0.54%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-20 ↗CWE-20: Improper Input Validation

Affected Products & Versions

Vendor Product Affected Versions
element-hq synapse < 1.120.1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.536%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2024-11-15T17:11:13
Published2024-12-03T16:58:30
Last Updated2024-12-03T19:06:11

LINK COPIED TO CLIPBOARD