cbcvebase.
CVE-2025-30355
published 2025-03-27

CVE-2025-30355: Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0…

PriorityP274high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
1.16%
63.5th percentile
Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited in the wild and has been fixed in Synapse v1.127.1. No known workarounds are available.

Affected

3 ranges
VendorProductVersion rangeFixed in
debianmatrix-synapse< matrix-synapse 1.121.0-6 (forky)matrix-synapse 1.121.0-6 (forky)
element-hqsynapse< 1.127.11.127.1
matrixsynapse< 1.127.11.127.1

Detection & IOCsextracted from sources · hover to see the quote

  • Synapse versions up to and including 1.127.0 are vulnerable; upgrade to v1.127.1 or later to remediate. Monitor for federation disruptions originating from unexpected remote servers as a potential exploitation indicator.
  • This vulnerability has been actively exploited in the wild. Treat any sudden loss of Matrix federation capability as a potential indicator of exploitation.
  • ·No known workarounds are available; the only mitigation is upgrading to the fixed version.
  • ·Debian (forky/sid) has backported the fix into package version 1.121.0-6, so Debian users on those tracks are protected even without upgrading to upstream 1.127.1.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vulncheck7.1HIGH
vendor_debian7.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.