Input validation error in Synapse - #VU139986
Published: July 29, 2026
Synapse
Detailed vulnerability description
The vulnerability allows a remote attacker to evade external rate-limiting.
The vulnerability exists due to improper input validation in HTTP request path handling when processing crafted request paths with extraneous path segments. A remote attacker can send a specially crafted request to evade external rate-limiting.
The Client-Server API, Federation API, Synapse Admin API, and Key Server API are not affected by this issue.