Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /sendjoin, /sendleave, and /invite may not be correctly signed, or may not come from the expected servers.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-18835.json"