CVE-2025-61672
published 2025-10-08CVE-2025-61672: Synapse is an open source Matrix homeserver implementation. Lack of validation for device keys in Synapse before 1.138.3 and in Synapse 1.139.0 allow an…
PriorityP432medium5.3CVSS 4.0
AVNACLATNPRLUINVCNVILVALSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.43%
35.2th percentile
Synapse is an open source Matrix homeserver implementation. Lack of validation for device keys in Synapse before 1.138.3 and in Synapse 1.139.0 allow an attacker registered on the victim homeserver to degrade federation functionality, unpredictably breaking outbound federation to other homeservers. The issue is patched in Synapse 1.138.3, 1.138.4, 1.139.1, and 1.139.2. Note that even though 1.138.3 and 1.139.1 fix the vulnerability, they inadvertently introduced an unrelated regression. For this reason, the maintainers of Synapse recommend skipping these releases and upgrading straight to 1.138.4 and 1.139.2.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | matrix-synapse | < matrix-synapse 1.139.2-1 (forky) | matrix-synapse 1.139.2-1 (forky) |
| element-hq | synapse | < 1.138.3 | 1.138.3 |
| element-hq | synapse | — | — |
CVSS provenance
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-61672: Synapse is an open source Matrix homeserver implementation
osv·2025-10-08·CVSS 5.3
CVE-2025-61672 [MEDIUM] CVE-2025-61672: Synapse is an open source Matrix homeserver implementation
Synapse is an open source Matrix homeserver implementation. Lack of validation for device keys in Synapse before 1.138.3 and in Synapse 1.139.0 allow an attacker registered on the victim homeserver to degrade federation functionality, unpredictably breaking outbound federation to other homeservers. The issue is patched in Synapse 1.138.3, 1.138.4, 1.139.1, and 1.139.2. Note that even though 1.138.3 and 1.139.1 fix the vulnerability, they inadvertently introduced an unrelated regression. For this reason, the maintainers of Synapse recommend skipping these releases and upgrading straight to 1.138.4 and 1.139.2.
GHSA
Synapse's invalid device keys degrade federation functionality
ghsa·2025-10-08
CVE-2025-61672 [MEDIUM] CWE-1287 Synapse's invalid device keys degrade federation functionality
Synapse's invalid device keys degrade federation functionality
### Impact
Lack of validation for device keys in Synapse before 1.138.3 and in Synapse 1.139.0 allow an attacker registered on the victim homeserver to degrade federation functionality, unpredictably breaking outbound federation to other homeservers.
### Patches
Patched in Synapse 1.138.3, 1.138.4, 1.139.1, and 1.139.2.
Note that even though 1.138.3 and 1.139.1 fix the vulnerability, they inadvertently introduced an unrelated regression. For this reason, it is recommend to skip these releases and upgrading straight to 1.138.4 and 1.139.2.
### Workarounds
The vulnerability can only be exploited by users registered on the victim homeserver.
OSV
Synapse's invalid device keys degrade federation functionality
osv·2025-10-08
CVE-2025-61672 [MEDIUM] Synapse's invalid device keys degrade federation functionality
Synapse's invalid device keys degrade federation functionality
### Impact
Lack of validation for device keys in Synapse before 1.138.3 and in Synapse 1.139.0 allow an attacker registered on the victim homeserver to degrade federation functionality, unpredictably breaking outbound federation to other homeservers.
### Patches
Patched in Synapse 1.138.3, 1.138.4, 1.139.1, and 1.139.2.
Note that even though 1.138.3 and 1.139.1 fix the vulnerability, they inadvertently introduced an unrelated regression. For this reason, it is recommend to skip these releases and upgrading straight to 1.138.4 and 1.139.2.
### Workarounds
The vulnerability can only be exploited by users registered on the victim homeserver.
Red Hat
matrix-synapse: Synapse: Lack of device key validation leads to federation degradation
vendor_redhat·2025-10-08·CVSS 5.3
CVE-2025-61672 [MEDIUM] CWE-1286 matrix-synapse: Synapse: Lack of device key validation leads to federation degradation
matrix-synapse: Synapse: Lack of device key validation leads to federation degradation
Synapse is an open source Matrix homeserver implementation. Lack of validation for device keys in Synapse before 1.138.3 and in Synapse 1.139.0 allow an attacker registered on the victim homeserver to degrade federation functionality, unpredictably breaking outbound federation to other homeservers. The issue is patched in Synapse 1.138.3, 1.138.4, 1.139.1, and 1.139.2. Note that even though 1.138.3 and 1.139.1 fix the vulnerability, they inadvertently introduced an unrelated regression. For this reason, the maintainers of Synapse recommend skipping these releases and upgrading straight to 1.138.4 and 1.139.2.
A flaw was found in Synapse, an open source Matrix homeserver implementation. This vulnerabili
Debian
CVE-2025-61672: matrix-synapse - Synapse is an open source Matrix homeserver implementation. Lack of validation f...
vendor_debian·2025·CVSS 5.3
CVE-2025-61672 [MEDIUM] CVE-2025-61672: matrix-synapse - Synapse is an open source Matrix homeserver implementation. Lack of validation f...
Synapse is an open source Matrix homeserver implementation. Lack of validation for device keys in Synapse before 1.138.3 and in Synapse 1.139.0 allow an attacker registered on the victim homeserver to degrade federation functionality, unpredictably breaking outbound federation to other homeservers. The issue is patched in Synapse 1.138.3, 1.138.4, 1.139.1, and 1.139.2. Note that even though 1.138.3 and 1.139.1 fix the vulnerability, they inadvertently introduced an unrelated regression. For this reason, the maintainers of Synapse recommend skipping these releases and upgrading straight to 1.138.4 and 1.139.2.
Scope: local
forky: resolved (fixed in 1.139.2-1)
sid: resolved (fixed in 1.139.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/element-hq/synapse/commit/26aaaf9e48fff80cf67a20c691c75d670034b3c1https://github.com/element-hq/synapse/commit/7069636c2d6d1ef2022287addf3ed8b919ef2740https://github.com/element-hq/synapse/pull/17097https://github.com/element-hq/synapse/releases/tag/v1.138.3https://github.com/element-hq/synapse/releases/tag/v1.139.1https://github.com/element-hq/synapse/security/advisories/GHSA-fh66-fcv5-jjfr
2025-10-08
Published