Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| matrix-synapse(PyPI) | 0 | 1.5.0 | N/A |
CVSS Metrics