CVE-2018-10657

HIGH EXPLOITED IN THE WILD

Matrix Synapse < 0.28.1 - Denial of Service via Malicious Event Depth Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2018-10657 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).

Description

Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018.

Scores

CVSS v3 7.5
EPSS 0.0151
EPSS Percentile 71.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

VulnCheck KEV 2018-05-01
InTheWild.io 2018-06-07
CWE
CWE-20
Status published
Products (2)
matrix/synapse < 0.28.1
pypi/matrix-synapse 0 - 0.28.1PyPI
Published May 02, 2018
Tracked Since Feb 18, 2026