PT-2025-41273 · Synapse · Synapse

Dkasak

·

Published

2025-10-07

·

Updated

2025-10-08

·

CVE-2025-61672

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Synapse versions prior to 1.138.3 Synapse version 1.139.0
Description Synapse is an open source Matrix homeserver implementation. Insufficient validation of device keys in affected versions allows an attacker registered on the victim homeserver to disrupt federation functionality, potentially breaking outbound federation to other homeservers.
Recommendations Upgrade to Synapse version 1.138.4 or later. Upgrade to Synapse version 1.139.2 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-61672
GHSA-FH66-FCV5-JJFR
OPENSUSE-SU-2025:15603-1

Affected Products

Synapse