{"api_version":"v1","generated_at":"2026-10-08T04:30:00+00:00","product":{"cve_count":24,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-matrix-org-synapse-67a51f5a9e0a","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/synapse","name":"synapse","next_cursor":null,"observations":[{"affected":"< 1.95.1","affected_versions_present":true,"cve_id":"CVE-2023-43796","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-43796","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-13T17:13:30.615Z","patch_url":"https://github.com/matrix-org/synapse/commit/daec55e1fe120c564240c5386e77941372bf458f","primary_source":"","published":"2023-10-31T16:52:48.505Z"},{"affected":"< 1.94.0","affected_versions_present":true,"cve_id":"CVE-2023-45129","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-45129","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-13T17:13:47.801Z","patch_url":"https://github.com/matrix-org/synapse/pull/16360","primary_source":"","published":"2023-10-10T17:17:11.146Z"},{"affected":">= 1.66.0, < 1.93.0","affected_versions_present":true,"cve_id":"CVE-2023-41335","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-41335","fixed":"1.93.0.","last_modified":"2025-02-13T17:09:01.354Z","patch_url":"https://github.com/matrix-org/synapse/security/advisories/GHSA-4f74-84v3-j9q5","primary_source":"","published":"2023-09-26T20:51:29.741Z"},{"affected":">= 0.34.0, < 1.93.0","affected_versions_present":true,"cve_id":"CVE-2023-42453","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-42453","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-06-18T14:11:32.728Z","patch_url":"https://github.com/matrix-org/synapse/pull/16327","primary_source":"","published":"2023-09-26T20:49:23.365Z"},{"affected":"< 1.85.0","affected_versions_present":true,"cve_id":"CVE-2023-32683","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-32683","fixed":"1.85.0.","last_modified":"2025-02-13T16:54:58.218Z","patch_url":"https://github.com/matrix-org/synapse/security/advisories/GHSA-98px-6486-j7qc","primary_source":"","published":"2023-06-06T18:24:30.457Z"},{"affected":"< 1.85.0","affected_versions_present":true,"cve_id":"CVE-2023-32682","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-32682","fixed":"1.85.0.","last_modified":"2025-02-13T16:54:57.207Z","patch_url":"https://github.com/matrix-org/synapse/security/advisories/GHSA-26c5-ppr8-f33p","primary_source":"","published":"2023-06-06T18:20:14.377Z"},{"affected":">= 1.62.0, < 1.68.0","affected_versions_present":true,"cve_id":"CVE-2022-39374","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-39374","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-13T16:33:00.253Z","patch_url":"https://github.com/matrix-org/synapse/pull/13723","primary_source":"","published":"2023-05-26T13:44:44.113Z"},{"affected":"< 1.69.0","affected_versions_present":true,"cve_id":"CVE-2022-39335","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-39335","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-13T16:32:59.633Z","patch_url":"https://github.com/matrix-org/synapse/pull/13823","primary_source":"","published":"2023-05-26T13:36:56.436Z"},{"affected":"< 1.74.0","affected_versions_present":true,"cve_id":"CVE-2023-32323","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-32323","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-02-13T16:50:32.310Z","patch_url":"https://github.com/matrix-org/synapse/pull/14642","primary_source":"","published":"2023-05-26T13:32:01.632Z"},{"affected":"< 1.53.0","affected_versions_present":true,"cve_id":"CVE-2022-41952","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-41952","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T16:35:54.250Z","patch_url":"https://github.com/matrix-org/synapse/pull/11784","primary_source":"","published":"2022-11-22T00:00:00.000Z"},{"affected":"< 1.62.0","affected_versions_present":true,"cve_id":"CVE-2022-31152","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-31152","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T17:32:15.848Z","patch_url":"https://github.com/matrix-org/synapse/pull/13087","primary_source":"","published":"2022-09-02T20:00:16.000Z"},{"affected":"< 1.61.1","affected_versions_present":true,"cve_id":"CVE-2022-31052","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-31052","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-23T18:05:56.038Z","patch_url":"https://github.com/matrix-org/synapse/commit/fa1308061802ac7b7d20e954ba7372c5ac292333","primary_source":"","published":"2022-06-28T17:10:11.000Z"},{"affected":"< 1.47.1","affected_versions_present":true,"cve_id":"CVE-2021-41281","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-41281","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T03:08:31.942Z","patch_url":"https://github.com/matrix-org/synapse/commit/91f2bd090","primary_source":"","published":"2021-11-23T19:15:18.000Z"},{"affected":"< 1.41.1","affected_versions_present":true,"cve_id":"CVE-2021-39164","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-39164","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T01:58:18.118Z","patch_url":"https://github.com/matrix-org/synapse/commit/cb35df940a","primary_source":"","published":"2021-08-31T16:20:10.000Z"},{"affected":"< 1.41.1","affected_versions_present":true,"cve_id":"CVE-2021-39163","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-39163","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T01:58:18.227Z","patch_url":"https://github.com/matrix-org/synapse/commit/cb35df940a","primary_source":"","published":"2021-08-31T16:00:11.000Z"},{"affected":"< 1.33.2","affected_versions_present":true,"cve_id":"CVE-2021-29471","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-29471","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T22:11:05.476Z","patch_url":"https://github.com/matrix-org/synapse/security/advisories/GHSA-x345-32rc-8h85","primary_source":"","published":"2021-05-11T15:05:12.000Z"},{"affected":"< 1.28.0","affected_versions_present":true,"cve_id":"CVE-2021-21392","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-21392","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T18:09:15.930Z","patch_url":"https://github.com/matrix-org/synapse/security/advisories/GHSA-5wrh-4jwv-5w78","primary_source":"","published":"2021-04-12T21:50:14.000Z"},{"affected":"< 1.28.0","affected_versions_present":true,"cve_id":"CVE-2021-21393","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-21393","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T18:09:15.986Z","patch_url":"https://github.com/matrix-org/synapse/pull/9321","primary_source":"","published":"2021-04-12T21:35:14.000Z"},{"affected":"< 1.28.0","affected_versions_present":true,"cve_id":"CVE-2021-21394","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-21394","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T18:09:16.108Z","patch_url":"https://github.com/matrix-org/synapse/security/advisories/GHSA-w9fg-xffh-p362","primary_source":"","published":"2021-04-12T20:45:18.000Z"},{"affected":"< 1.27.0","affected_versions_present":true,"cve_id":"CVE-2021-21333","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-21333","fixed":"1.27.0.","last_modified":"2024-08-03T18:09:15.578Z","patch_url":"https://github.com/matrix-org/synapse/pull/9200","primary_source":"","published":"2021-03-26T20:00:19.000Z"},{"affected":"< 1.27.0","affected_versions_present":true,"cve_id":"CVE-2021-21332","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-21332","fixed":"1.27.0.","last_modified":"2024-08-03T18:09:15.157Z","patch_url":"https://github.com/matrix-org/synapse/pull/9200","primary_source":"","published":"2021-03-26T19:55:17.000Z"},{"affected":"< 1.25.0","affected_versions_present":true,"cve_id":"CVE-2021-21273","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-21273","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-03T18:09:15.293Z","patch_url":"https://github.com/matrix-org/synapse/security/advisories/GHSA-v936-j8gp-9q3p","primary_source":"","published":"2021-02-26T17:25:29.000Z"},{"affected":">=0.99.0, < 1.25.0","affected_versions_present":true,"cve_id":"CVE-2021-21274","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-21274","fixed":"1.25.0.","last_modified":"2024-08-03T18:09:15.070Z","patch_url":"https://github.com/matrix-org/synapse/security/advisories/GHSA-2hwx-mjrm-v3g8","primary_source":"","published":"2021-02-26T17:25:16.000Z"},{"affected":"< 1.23.1","affected_versions_present":true,"cve_id":"CVE-2020-26257","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-26257","fixed":"1.23.1.","last_modified":"2024-08-04T15:56:03.561Z","patch_url":"https://github.com/matrix-org/synapse/pull/8776","primary_source":"","published":"2020-12-09T18:25:15.000Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"matrix-org"}}
