Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited in the wild and has been fixed in Synapse v1.127.1. No known workarounds are available.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Mar 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited in the wild and has been fixed in Synapse v1.127.1. No known workarounds are available. | |
Title | Synapse vulnerable to federation denial of service via malformed events | |
Weaknesses | CWE-20 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-03-27T00:59:27.996Z
Updated: 2025-03-27T00:59:27.996Z
Reserved: 2025-03-21T14:12:06.270Z
Link: CVE-2025-30355

No data.

Status : Received
Published: 2025-03-27T01:15:12.500
Modified: 2025-03-27T01:15:12.500
Link: CVE-2025-30355

No data.