Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3463 | Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user's /sync functionality. Synapse 1.120.1 rejects such invalid invites received over federation and restores the ability to sync for affected users. |
Github GHSA |
GHSA-f3r3-h2mq-hx2h | Synapse allows a a malformed invite to break the invitee's `/sync` |
Tue, 26 Aug 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Matrix
Matrix synapse |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Matrix
Matrix synapse |
|
| Metrics |
cvssV3_1
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 03 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Element-hq
Element-hq synapse |
|
| CPEs | cpe:2.3:a:element-hq:synapse:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Element-hq
Element-hq synapse |
|
| Metrics |
ssvc
|
Tue, 03 Dec 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | A malformed invite can break the invitee's `/sync` | Synapse allows a a malformed invite to break the invitee's `/sync` |
Tue, 03 Dec 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user's /sync functionality. Synapse 1.120.1 rejects such invalid invites received over federation and restores the ability to sync for affected users. | |
| Title | A malformed invite can break the invitee's `/sync` | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-03T19:06:11.082Z
Reserved: 2024-11-15T17:11:13.444Z
Link: CVE-2024-52815
Updated: 2024-12-03T19:06:00.818Z
Status : Analyzed
Published: 2024-12-03T17:15:12.267
Modified: 2025-08-26T15:02:27.547
Link: CVE-2024-52815
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA