Insufficient verification of data authenticity in Synapse - #VU139993
Published: July 29, 2026
Synapse
Detailed vulnerability description
The vulnerability allows a remote attacker to spoof the origin of to-device messages.
The vulnerability exists due to improper origin validation in to-device message handling when processing federation messages from remote homeservers. A remote attacker can send a specially crafted to-device message with a spoofed sender field to spoof the origin of to-device messages.
Homeservers that do not federate or only participate in a closed, trusted federation are not affected.