Interpretation Conflict in Synapse - CVE-2024-53863
Published: December 3, 2024 / Updated: April 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to invoke potentially untrustworthy decoders.
The vulnerability exists due to improper restriction of processed file formats in thumbnail generation when processing a specially crafted request. A remote attacker can send a specially crafted request to invoke potentially untrustworthy decoders.
Instances with the dynamic_thumbnails option enabled are affected.
Affected software
Fedora
matrix-synapse
How to mitigate CVE-2024-53863
matrix-synapse - addressed in versions 1.111.1-3.fc40, 1.118.0-3.fc41