Improper Validation of Specified Type of Input in Synapse - CVE-2025-61672
Published: April 23, 2026
Synapse
Detailed vulnerability description
The vulnerability allows a remote user to degrade federation functionality.
The vulnerability exists due to improper validation of specified type of input in device key validation when processing device keys. A remote user can register and use invalid device keys to degrade federation functionality.
The issue can unpredictably break outbound federation to other homeservers.