Input validation error in Synapse - CVE-2025-30355
Published: March 31, 2025
Vulnerability identifier: #VU106284
CSH Severity: High
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-30355
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
The vulnerability is being exploited in the wild
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote user can pass specially crafted events to the application and prevent it from federating with other servers.
Note, the vulnerability is being exploited in the wild.
Affected software
Synapse
Fedora
matrix-synapse
Fedora
matrix-synapse
How to mitigate CVE-2025-30355
Install updates from vendor's website.
Synapse - update to 1.127.1
matrix-synapse - addressed in versions 1.111.1-4.fc40, 1.118.0-4.fc41, 1.127.1-1.fc42
matrix-synapse - addressed in versions 1.111.1-4.fc40, 1.118.0-4.fc41, 1.127.1-1.fc42