GHSA-mp92-3jfm-3575 · Severity: medium · Ecosystem: pip — Synapse vulnerable to leak of remote user device information
Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver. System administrators are encouraged to upgrade to Synapse 1.95.1 or 1.96.0rc1 to receive a patch. As a workaround, the `federation_domain_whitelist` can be used to limit federation traffic with a homeserver.
Conclusion & alert: CVE-2023-43796 is rated Moderate Risk (41/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.90%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.23% | 0.90% | +0.66% |
| 2 | 2026-06-11 | 0.27% | 0.23% | -0.03% |
| 3 | 2026-05-24 | — | 0.27% | — |
Full EPSS history (16 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 3.1 | MEDIUM |
|
3.9 | 1.4 | [email protected] |
| 5.3 | 3.1 | MEDIUM |
|
3.9 | 1.4 | [email protected] |
GHSA-mp92-3jfm-3575 · Severity: medium · Ecosystem: pip — Synapse vulnerable to leak of remote user device information
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2023-43796: 1 source package rows (synapse); 34 state rows across 6 repos (3.18-community, 3.19-community, 3.20-community, 3.21-community, 3.22-community, edge-community); fixed 6, open 28. | https://security.alpinelinux.org/vuln/CVE-2023-43796 |
debian
|
not yet assigned | CVE-2023-43796 not yet assigned priority: Debian including 1 source packages (matrix-synapse), 2 status rows across 2 suites (forky, sid): resolved 2. | https://security-tracker.debian.org/tracker/CVE-2023-43796 |
gentoo
|
low | CVE-2023-43796: 1 GLSA(s) (202401-12), 1 atom(s) (net-im/synapse); latest impact low. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2023-43796 |
ubuntu
|
medium | CVE-2023-43796 medium priority: Ubuntu including 1 source packages (matrix-synapse), 10 status rows across 10 suites (bionic, focal, jammy, lunar, mantic, noble, oracular, trusty, upstream, xenial): ignored 4, released 4, not-affected 2. | https://ubuntu.com/security/CVE-2023-43796 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| matrix | synapse | < 1.95.1 | cpe:2.3:a:matrix:synapse:*:*:*:*:*:*:*:* |
| fedoraproject | fedora | 38 | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* |
| fedoraproject | fedora | 39 | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |