Input validation error in Synapse - CVE-2023-45129
Published: October 10, 2023 / Updated: May 4, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper input validation in server ACL event handling when processing malicious server ACL events. A remote privileged user can send a malicious server ACL event to cause a denial of service.
Homeservers running on a closed federation are not affected.
Affected software
Gentoo Linux
Fedora
matrix-synapse
net-im/synapse
How to mitigate CVE-2023-45129
matrix-synapse - addressed in versions 1.80.0-7.fc37, 1.94.0-2.fc38, 1.94.0-2.fc39
net-im/synapse - update to 1.96.0