An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NMatrix Sydent
APPMatrix< 1.0.3Matrix Synapse
APPMatrix< 0.99.3.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
Related vulnerabilities
CVE-2023-38686CRITICAL9.3PL ✓same product
Brak weryfikacji certyfikatu SMTP TLS w Matrix Sydent — podatność MITM
CVE-2019-18835CRITICAL9.8PL ✓same product
Matrix Synapse: błąd weryfikacji podpisów w federation API
CVE-2025-30355HIGH7.1same product
Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when re...
CVE-2024-52805HIGH8.2same product
Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in ce...
CVE-2024-37302HIGH7.5same product
Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attac...