Incorrect authorization in Synapse - CVE-2022-39374

 

Incorrect authorization in Synapse - CVE-2022-39374

Published: May 24, 2023 / Updated: May 4, 2026


Vulnerability identifier: #VU129606
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2022-39374
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Synapse
Software vendor:
Matrix.org

Description

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper authorization in event authorization rules during state resolution when processing room state from a joined malicious homeserver. A remote user can trick Synapse into accepting previously rejected events to cause a denial of service.

Exploitation is possible only when the homeserver is joined to rooms that include or invite members of untrusted homeservers.


Remediation

Install security update from vendor's website.

External links