Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-05-16
10 active CVEs reported via OSV.dev
URL previews of unusual or maliciously-crafted pages can crash Synapse media repositories or Synapse monoliths
Cross-site scripting (XSS) vulnerability in the password reset endpoint
Synapse has improper checks for deactivated users during login
Denial of service attack via .well-known lookups
Synapse V2 state resolution weakness allows Denial of Service (DoS)
Path traversal in Matrix Synapse
Improper authorisation of members discloses room membership to non-members
Cross-site scripting (XSS) vulnerability in the fallback authentication endpoint
Synapse does not apply enough checks to servers requesting auth events of events in a room
Uncontrolled Resource Consumption in Matrix Synapse
Other Communication projects in the Python ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for Matrix Synapse — without relying on volunteer maintainers.
Talk to an Expert →