#VU127001 Input validation error in Synapse - CVE-2024-52815
Published: December 3, 2024 / Updated: April 23, 2026
Synapse
Matrix.org
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in invite validation over federation when processing invites received over federation. A remote attacker can send a specially crafted invite to cause a denial of service.
The issue can disrupt the invited user's /sync functionality.