Cross-site scripting in Synapse - CVE-2021-21333
Published: March 25, 2021 / Updated: May 4, 2026
Vulnerability details
The vulnerability allows a remote user to inject forged content into notification emails.
The vulnerability exists due to improper neutralization of input during web page generation in email notification templates when rendering missed message notifications. A remote user can send crafted content to inject forged content into notification emails.
The account expiry notification path is also affected, but that injection is not controllable by an attacker.
Affected software
Fedora
matrix-synapse
How to mitigate CVE-2021-21333
matrix-synapse - addressed in versions 1.38.0-2.fc34, 1.38.1-1.fc34