CVE-2025-61672 Details
Description
Synapse is an open source Matrix homeserver implementation. Lack of validation for device keys in Synapse before 1.138.3 and in Synapse 1.139.0 allow an attacker registered on the victim homeserver to degrade federation functionality, unpredictably breaking outbound federation to other homeservers. The issue is patched in Synapse 1.138.3, 1.138.4, 1.139.1, and 1.139.2. Note that even though 1.138.3 and 1.139.1 fix the vulnerability, they inadvertently introduced an unrelated regression. For this reason, the maintainers of Synapse recommend skipping these releases and upgrading straight to 1.138.4 and 1.139.2.
A vulnerability exists in Element Synapse Matrix homeserver implementations prior to version 1.138.3 and in version 1.139.0. This vulnerability arises from inadequate validation of device keys, allowing attackers registered on the victim homeserver to disrupt federation functionality. The lack of proper validation can unpredictably break outbound federation to other homeservers.
Users can upgrade to Synapse versions 1.138.4 or 1.139.2, both of which address this vulnerability. However, it is recommended to skip versions 1.138.3 and 1.139.1, as they introduced an unrelated regression.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 8, 2025CISA-ADP
Assessed Oct 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/element-hq/synapse/commit/26aaaf9e48fff80cf67a20c691c75d670034b3c1 | [email protected] | Source CodeVendor |
| https://github.com/element-hq/synapse/commit/7069636c2d6d1ef2022287addf3ed8b919ef2740 | [email protected] | Source CodeVendor |
| https://github.com/element-hq/synapse/pull/17097 | [email protected] | Issue TrackingVendor |
| https://github.com/element-hq/synapse/releases/tag/v1.138.3 | [email protected] | Release NotesVendor |
| https://github.com/element-hq/synapse/releases/tag/v1.139.1 | [email protected] | Release NotesVendor |
| https://github.com/element-hq/synapse/security/advisories/GHSA-fh66-fcv5-jjfr | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1287 | Improper Validation of Specified Type of Input | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| element-hq synapse | < 1.138.3 (semver) = 1.139.0 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 8, 2025 | New CVE Received | [email protected] |
Volerion