---
title: "CVE-2020-26257\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2020-26257?format=md
keywords: index, follow
---

# CVE-2020-26257

Publication date 9 December 2020

Last updated 26 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**6.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2020-26257?format=md#impact-score)

Toggle side navigation

## Description

Matrix is an ecosystem for open federated Instant Messaging and VoIP.
Synapse is a reference "homeserver" implementation of Matrix. A malicious
or poorly-implemented homeserver can inject malformed events into a room by
specifying a different room id in the path of a `/send\_join`,
`/send\_leave`, `/invite` or `/exchange\_third\_party\_invite` request. This
can lead to a denial of service in which future events will not be
correctly sent to other servers over federation. This affects any server
which accepts federation requests from untrusted servers. The Matrix
Synapse reference implementation before version 1.23.1 the implementation
is vulnerable to this injection attack. Issue is fixed in version 1.23.1.
As a workaround homeserver administrators could limit access to the
federation API to trusted servers (for example via
`federation\_domain\_whitelist`).

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| matrix-synapse | 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Ignored end of life, was needs-triage |
| 22.04 LTS jammy | Needs evaluation |
| 21.10 impish | Ignored end of life |
| 21.04 hirsute | Ignored end of life |
| 20.10 groovy | Ignored end of life |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

6.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26257)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-26257)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2020-26257)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2020-26257)

### Other references

* <https://github.com/matrix-org/synapse/security/advisories/GHSA-hxmp-pqch-c8mm>
* <https://github.com/matrix-org/synapse/pull/8776>
* <https://github.com/matrix-org/synapse/commit/3ce2f303f15f6ac3dc352298972dc6e04d9b7a8b>
* <https://github.com/matrix-org/synapse/blob/develop/CHANGES.md#synapse-1231-2020-12-09>
* <https://www.cve.org/CVERecord?id=CVE-2020-26257>
