PT-2025-41273 · Synapse · Synapse

·

CVE-2025-61672

·

Published

2025-10-07

·

Updated

2026-07-07

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Synapse versions prior to 1.138.3 Synapse version 1.139.0
Description Synapse is an open source Matrix homeserver implementation. Insufficient validation of device keys in affected versions allows an attacker registered on the victim homeserver to disrupt federation functionality, potentially breaking outbound federation to other homeservers.
Recommendations Upgrade to Synapse version 1.138.4 or later. Upgrade to Synapse version 1.139.2 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-61672
GHSA-FH66-FCV5-JJFR
OPENSUSE-SU-2025:15603-1
PYSEC-2026-1612

Affected Products

Synapse