Improper handling of exceptional conditions in Synapse - #VU139989
Published: July 29, 2026
Synapse
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a client to act as though it has logged out and destroy its cryptographic state.
The vulnerability exists due to improper error handling in Synapse federation request handling when processing client-issued requests concerning remote users or remote rooms, or messages in rooms moderated by a malicious policy server. A remote attacker can operate a malicious homeserver or policy server that returns 401 unauthorized federation responses to cause a client to act as though it has logged out and destroy its cryptographic state.
Homeservers that do not federate or only participate in a closed, trusted federation are not affected. If recovery mechanisms are unavailable, encrypted message history can be irreversibly lost.