First published: Thu Mar 27 2025(Updated: )
### Impact A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited in the wild. ### Patches Fixed in Synapse v1.127.1. ### Workarounds Closed federation environments of trusted servers or non-federating installations are not affected. ### For more information If you have any questions or comments about this advisory, please email us at [security at element.io](mailto:security@element.io).
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
pip/matrix-synapse | <1.127.1 | 1.127.1 |
Synapse | <1.127.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30355 is classified as a high severity vulnerability due to its potential to disrupt federated communications in Synapse.
To fix CVE-2025-30355, update Synapse to version 1.127.1 or later.
CVE-2025-30355 affects Synapse versions up to and including 1.127.0.
If exploited, CVE-2025-30355 can prevent a Synapse server from federating with other servers, disrupting communication.
Support for versions affected by CVE-2025-30355 is limited, and upgrading is strongly recommended to ensure security.