PT-2025-41273 · Synapse · Synapse
Dkasak
·
Published
2025-10-07
·
Updated
2025-10-08
·
CVE-2025-61672
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Synapse versions prior to 1.138.3
Synapse version 1.139.0
Description
Synapse is an open source Matrix homeserver implementation. Insufficient validation of device keys in affected versions allows an attacker registered on the victim homeserver to disrupt federation functionality, potentially breaking outbound federation to other homeservers.
Recommendations
Upgrade to Synapse version 1.138.4 or later.
Upgrade to Synapse version 1.139.2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Synapse