OSS Support Hub / Communication

Python Communication

Matrix Synapse

Reference homeserver for the Matrix open standard for decentralised communication

Project Health at a Glance

Live data from GitHub and PyPI, updated daily.

GitHub Stars
📦
Latest Release
🔄
Avg. Release Cadence
🐛
Open Issues
📅
Unknown
Last Commit
🔒
10
Active CVEs

Data last fetched: 2026-05-16

Known Vulnerabilities

10 active CVEs reported via OSV.dev

URL previews of unusual or maliciously-crafted pages can crash Synapse media repositories or Synapse monoliths

Published: 2022-06-29 Fixed in: 1.61.1

Cross-site scripting (XSS) vulnerability in the password reset endpoint

Published: 2021-03-26 Fixed in: 1.27.0

Synapse has improper checks for deactivated users during login

Published: 2023-06-06 Fixed in: 1.85.0

Denial of service attack via .well-known lookups

Published: 2021-03-01 Fixed in: 1.25.0

Synapse V2 state resolution weakness allows Denial of Service (DoS)

Published: 2024-04-23 Fixed in: 1.105.1

Path traversal in Matrix Synapse

Published: 2021-11-23 Fixed in: 1.47.1

Improper authorisation of members discloses room membership to non-members

Published: 2021-09-01 Fixed in: 1.41.1

Cross-site scripting (XSS) vulnerability in the fallback authentication endpoint

Published: 2020-10-16 Fixed in: 1.21.0

Synapse does not apply enough checks to servers requesting auth events of events in a room

Published: 2023-05-24 Fixed in: 1.69.0

Uncontrolled Resource Consumption in Matrix Synapse

Published: 2022-04-01 Fixed in: 1.53.0

Alternatives to Matrix Synapse

Other Communication projects in the Python ecosystem worth evaluating.

Support Options for Matrix Synapse

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Matrix Synapse — without relying on volunteer maintainers.

Talk to an Expert →