Input validation error in Synapse - CVE-2025-30355

 

Input validation error in Synapse - CVE-2025-30355

Published: March 31, 2025


Vulnerability identifier: #VU106284
CSH Severity: High
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-30355
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote user to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote user can pass specially crafted events to the application and prevent it from federating with other servers.

Note, the vulnerability is being exploited in the wild.


Affected software

Synapse
Fedora
matrix-synapse

How to mitigate CVE-2025-30355

Install updates from vendor's website.

Synapse - update to 1.127.1
matrix-synapse - addressed in versions 1.111.1-4.fc40, 1.118.0-4.fc41, 1.127.1-1.fc42

External References

Related Security Bulletins