CVE-2025-61672
Description
A flaw was found in Synapse, an open source Matrix homeserver implementation. This vulnerability allows an attacker registered on the victim homeserver to degrade federation functionality, unpredictably breaking outbound federation to other homeservers via lack of validation for device keys.
Statement
This flaw is rated MODERATE because the highest threat of this flaw is to system availability. However, we further do not ship the vulnerable versions in fedora. Hence, it will be downgraded to a LOW.
Understanding the Weakness (CWE)
Other
Technical Impact: Varies by Context
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.