CVE-2025-61672

Description

A flaw was found in Synapse, an open source Matrix homeserver implementation. This vulnerability allows an attacker registered on the victim homeserver to degrade federation functionality, unpredictably breaking outbound federation to other homeservers via lack of validation for device keys.

Statement

This flaw is rated MODERATE because the highest threat of this flaw is to system availability. However, we further do not ship the vulnerable versions in fedora. Hence, it will be downgraded to a LOW.

Understanding the Weakness (CWE)

Other

Technical Impact: Varies by Context

Frequently Asked Questions

Want to get errata notifications? Sign up here.