Security Advisory

CVE-2025-30355

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-03-27 00:59:27
Last updated 2025-03-27 13:47:50
Assigner GitHub_M
State PUBLISHED

Description

Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited in the wild and has been fixed in Synapse v1.127.1. No known workarounds are available.