{"id":"CVE-2024-52815","aliases":["GHSA-f3r3-h2mq-hx2h","PYSEC-2026-1611"],"url":"https://o3.security/vulnerability/CVE-2024-52815","summary":"Synapse allows a a malformed invite to break the invitee's `/sync`","details":"Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user's /sync functionality. Synapse 1.120.1 rejects such invalid invites received over federation and restores the ability to sync for affected users.","published":"2024-12-03T16:58:30.877Z","modified":"2026-08-12T03:51:43.526562151Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"matrix-synapse","fixedVersion":"1.120.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/52xxx/CVE-2024-52815.json"},{"type":"ADVISORY","url":"https://github.com/element-hq/synapse/security/advisories/GHSA-f3r3-h2mq-hx2h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52815"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:43.526562151Z"}}