Input validation error in Synapse - #VU139988
Published: July 29, 2026
Synapse
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper input validation in the MSC4186 Sliding Sync response handling when processing room metadata and user profile data. A remote user can join a room with invalid name, avatar, or profile data to cause a denial of service.
Instances that only have trusted local users and either do not federate or only participate in a closed, trusted federation are not affected.