CVE-2025-30355
published 2025-03-27CVE-2025-30355: Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0…
PriorityP274high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
1.16%
63.5th percentile
Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited in the wild and has been fixed in Synapse v1.127.1. No known workarounds are available.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | matrix-synapse | < matrix-synapse 1.121.0-6 (forky) | matrix-synapse 1.121.0-6 (forky) |
| element-hq | synapse | < 1.127.1 | 1.127.1 |
| matrix | synapse | < 1.127.1 | 1.127.1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Synapse versions up to and including 1.127.0 are vulnerable; upgrade to v1.127.1 or later to remediate. Monitor for federation disruptions originating from unexpected remote servers as a potential exploitation indicator. ↗
- →This vulnerability has been actively exploited in the wild. Treat any sudden loss of Matrix federation capability as a potential indicator of exploitation. ↗
- ·No known workarounds are available; the only mitigation is upgrading to the fixed version. ↗
- ·Debian (forky/sid) has backported the fix into package version 1.121.0-6, so Debian users on those tracks are protected even without upgrading to upstream 1.127.1. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vulncheck7.1HIGH
vendor_debian7.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Synapse vulnerable to federation denial of service via malformed events
ghsa·2025-03-27
CVE-2025-30355 [HIGH] CWE-20 Synapse vulnerable to federation denial of service via malformed events
Synapse vulnerable to federation denial of service via malformed events
### Impact
A malicious server can craft events with a `depth` outside the integer range allowed by Canonical JSON. When such an event is received by Synapse version up to 1.127.0, it prevents it from federating with other servers. The vulnerability has been exploited in the wild.
### Patches
Fixed in Synapse v1.127.1.
### Workarounds
Closed federation environments of trusted servers or non-federating installations are not affected.
### For more information
If you have any questions or comments about this advisory, please email us at [security at element.io](mailto:[email protected]).
OSV
CVE-2025-30355: Synapse is an open source Matrix homeserver implementation
osv·2025-03-27·CVSS 7.5
CVE-2025-30355 [HIGH] CVE-2025-30355: Synapse is an open source Matrix homeserver implementation
Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited in the wild and has been fixed in Synapse v1.127.1. No known workarounds are available.
OSV
Synapse vulnerable to federation denial of service via malformed events
osv·2025-03-27
CVE-2025-30355 [HIGH] Synapse vulnerable to federation denial of service via malformed events
Synapse vulnerable to federation denial of service via malformed events
### Impact
A malicious server can craft events with a `depth` outside the integer range allowed by Canonical JSON. When such an event is received by Synapse version up to 1.127.0, it prevents it from federating with other servers. The vulnerability has been exploited in the wild.
### Patches
Fixed in Synapse v1.127.1.
### Workarounds
Closed federation environments of trusted servers or non-federating installations are not affected.
### For more information
If you have any questions or comments about this advisory, please email us at [security at element.io](mailto:[email protected]).
VulnCheck
matrix synapse Improper Input Validation
vulncheck·2025·CVSS 7.1
CVE-2025-30355 [HIGH] matrix synapse Improper Input Validation
matrix synapse Improper Input Validation
Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited in the wild and has been fixed in Synapse v1.127.1. No known workarounds are available.
Affected: Element Synapse
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://github.com/element-hq/synapse/security/advisories/GHSA-v56r-hwv5-mxg6; https://nvd.nist.gov/vuln/detail/CVE-2025-30355; https://www.cve.org/CVERecord?id=CVE-2025-30355; https://www.loginsoft.com/reports/annually/vulnerabili
Debian
CVE-2025-30355: matrix-synapse - Synapse is an open source Matrix homeserver implementation. A malicious server c...
vendor_debian·2025·CVSS 7.1
CVE-2025-30355 [HIGH] CVE-2025-30355: matrix-synapse - Synapse is an open source Matrix homeserver implementation. A malicious server c...
Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited in the wild and has been fixed in Synapse v1.127.1. No known workarounds are available.
Scope: local
forky: resolved (fixed in 1.121.0-6)
sid: resolved (fixed in 1.121.0-6)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-27
Published
Exploited in the wild