{"api_version":"v1","generated_at":"2026-10-07T22:40:00+00:00","product":{"cve_count":11,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-element-hq-synapse-6c3169d628c2","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/synapse","name":"synapse","next_cursor":null,"observations":[{"affected":"< 1.152.1","affected_versions_present":true,"cve_id":"CVE-2026-45078","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45078","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-29T15:31:44.793Z","patch_url":"https://github.com/element-hq/synapse/security/advisories/GHSA-8q93-326v-3m7g","primary_source":"","published":"2026-05-28T15:52:04.765Z"},{"affected":"< 1.152.1","affected_versions_present":true,"cve_id":"CVE-2026-45076","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45076","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-02T14:51:34.553Z","patch_url":"","primary_source":"","published":"2026-05-28T15:50:25.842Z"},{"affected":"< 1.138.3; = 1.139.0","affected_versions_present":true,"cve_id":"CVE-2025-61672","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-61672","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-15T16:11:07.284Z","patch_url":"","primary_source":"","published":"2025-10-08T14:55:06.378Z"},{"affected":"< 1.127.1","affected_versions_present":true,"cve_id":"CVE-2025-30355","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-30355","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-03-27T13:47:50.179Z","patch_url":"https://github.com/element-hq/synapse/commit/2277df2a1eb685f85040ef98fa21d41aa4cdd389","primary_source":"","published":"2025-03-27T00:59:27.996Z"},{"affected":"< 1.106","affected_versions_present":true,"cve_id":"CVE-2024-37303","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-37303","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-12-03T18:51:29.590Z","patch_url":"https://github.com/matrix-org/matrix-spec-proposals/pull/3916","primary_source":"","published":"2024-12-03T17:06:02.467Z"},{"affected":"< 1.106","affected_versions_present":true,"cve_id":"CVE-2024-37302","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-37302","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-03T18:56:17.082Z","patch_url":"","primary_source":"","published":"2024-12-03T17:04:15.839Z"},{"affected":"< 1.120.1","affected_versions_present":true,"cve_id":"CVE-2024-52805","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-52805","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-03T19:04:44.446Z","patch_url":"","primary_source":"","published":"2024-12-03T17:01:50.119Z"},{"affected":"< 1.120.1","affected_versions_present":true,"cve_id":"CVE-2024-52815","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-52815","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-03T19:06:11.082Z","patch_url":"","primary_source":"","published":"2024-12-03T16:58:30.877Z"},{"affected":">= 1.113.0rc1, < 1.120.1","affected_versions_present":true,"cve_id":"CVE-2024-53867","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-53867","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-03T19:07:19.919Z","patch_url":"","primary_source":"","published":"2024-12-03T16:52:01.596Z"},{"affected":"< 1.120.1","affected_versions_present":true,"cve_id":"CVE-2024-53863","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-53863","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-03T19:08:30.218Z","patch_url":"","primary_source":"","published":"2024-12-03T16:48:29.722Z"},{"affected":"< 1.105.1","affected_versions_present":true,"cve_id":"CVE-2024-31208","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-31208","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-13T17:47:51.943Z","patch_url":"https://github.com/element-hq/synapse/commit/55b0aa847a61774b6a3acdc4b177a20dc019f01a","primary_source":"","published":"2024-04-23T17:26:39.171Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"element-hq"}}
