CVE-2018-10657

HIGH EXPLOITED IN THE WILD

Matrix Synapse <0.28.1 - DoS

Title source: llm
STIX 2.1

Description

Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018.

Scores

CVSS v3 7.5
EPSS 0.0043
EPSS Percentile 62.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

VulnCheck KEV 2018-05-01
InTheWild.io 2018-06-07
CWE
CWE-20
Status published
Products (2)
matrix/synapse < 0.28.1
pypi/matrix-synapse 0 - 0.28.1PyPI
Published May 02, 2018
Tracked Since Feb 18, 2026