Vulnerabilities (CVE)

Filtered by vendor Matrix Subscribe
Filtered by product Synapse
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-18835 1 Matrix 1 Synapse 2020-08-24 7.5 HIGH 9.8 CRITICAL
Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers.