{"id":"DEBIAN-CVE-2025-61672","details":"Synapse is an open source Matrix homeserver implementation. Lack of validation for device keys in Synapse before 1.138.3 and in Synapse 1.139.0 allow an attacker registered on the victim homeserver to degrade federation functionality, unpredictably breaking outbound federation to other homeservers. The issue is patched in Synapse 1.138.3, 1.138.4, 1.139.1, and 1.139.2. Note that even though 1.138.3 and 1.139.1 fix the vulnerability, they inadvertently introduced an unrelated regression. For this reason, the maintainers of Synapse recommend skipping these releases and upgrading straight to 1.138.4 and 1.139.2.","modified":"2026-08-11T20:49:53.670669145Z","published":"2025-10-08T15:16:25.110Z","withdrawn":"2026-08-11T20:49:53.670668842Z","upstream":["CVE-2025-61672"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-61672"}],"affected":[{"package":{"name":"matrix-synapse","ecosystem":"Debian:14","purl":"pkg:deb/debian/matrix-synapse?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.139.2-1"}]}],"versions":["0.19.2+dfsg-3","0.19.2+dfsg-4","0.19.2+dfsg-5","0.19.2+dfsg-6","0.24.0+dfsg-1","0.27.2+dfsg-1","0.28.0+dfsg-1","0.28.0+dfsg-2","0.28.1+dfsg-1","0.29.1+dfsg-1","0.30.0+dfsg-1","0.31.0+dfsg-1","0.31.0+dfsg-2","0.31.1+dfsg-1","0.31.1+dfsg-2","0.31.2+dfsg-1","0.32.2+dfsg-1","0.33.0+dfsg-1","0.33.1+dfsg-1","0.33.2+dfsg-1","0.33.2+dfsg-2","0.33.2+dfsg-3","0.33.3-1","0.33.3-2","0.33.3.1-1","0.33.4-1","0.33.4-1~bpo9+1","0.33.8-1","0.33.9-2","0.33.9-2~bpo9+1","0.34.0-1","0.34.0-2","0.34.0-3","0.34.0-3~bpo9+1","0.34.0-3~bpo9+2","0.34.0~rc2-1","0.34.1.1-1","0.34.1.1-2","0.34.1.1-2~bpo9+1","0.34.1.1-3","0.34.1.1-3~bpo9+1","0.34.1.1-3~bpo9+2","0.34.1.1-4","0.99.0-1","0.99.0-1~bpo9+1","0.99.0-1~bpo9+2","0.99.0-1~bpo9+3","0.99.1.1-1","0.99.2-1","0.99.2-1~bpo9+1","0.99.2-1~bpo9+2","0.99.2-2","0.99.2-3","0.99.2-4","0.99.2-5","0.99.2-5~bpo9+1","0.99.2-6","0.99.3.2-1","0.99.5.1-1","0.99.5.2-1","1.0.0-1","1.0.0-2","1.0.0-2~bpo10+1","1.1.0-1","1.10.0-1","1.10.0-2","1.100.0-1","1.103.0-1","1.103.0-2","1.103.0-3","1.103.0-4","1.103.0-5","1.11.0-1","1.11.1-1","1.11.1-1~bpo10+1","1.116.0-1","1.116.0-2","1.116.0-3","1.116.0-4","1.12.0-1","1.12.0-1~bpo10+1","1.12.3-1","1.12.3-1~bpo10+1","1.12.4-1","1.12.4-1~bpo10+1","1.121.0-1","1.121.0-2","1.121.0-4","1.121.0-5","1.121.0-6","1.128.0-1","1.13.0-1","1.13.0-1~bpo10+1","1.136.0-1","1.15.0-1","1.15.1-1","1.15.1-1~bpo10+1","1.15.1-1~bpo10+2","1.15.2-1","1.16.0-1","1.17.0-1","1.17.0-1~bpo10+1","1.18.0-1","1.18.0-1~bpo10+1","1.19.0-1","1.19.0-1~bpo10+1","1.19.1-1","1.19.1-1~bpo10+1","1.19.1-1~bpo10+2","1.19.1-1~bpo10+3","1.19.2-1","1.19.3-1","1.2.1-1","1.2.1-1~bpo10+1","1.2.1-1~bpo10+2","1.2.1-2","1.20.0-1","1.20.1-1","1.20.1-1~bpo10+1","1.21.1-1","1.21.2-1","1.21.2-1~bpo10+1","1.22.1-1","1.22.1-1~bpo10+1","1.22.1-2","1.22.1-2~bpo10+1","1.23.0-1","1.23.0-1~bpo10+1","1.24.0-1","1.24.0-1~bpo10+1","1.24.0-2","1.25.0-1","1.25.0-1~bpo10+1","1.25.0-2","1.26.0-1","1.26.0-1~bpo10+1","1.26.0-1~bpo10+2","1.26.0-1~bpo10+3","1.26.0-2","1.26.0-3","1.27.0-1","1.27.0-1~bpo10+1","1.27.0-1~bpo10+2","1.27.0-1~bpo10+3","1.28.0-1","1.28.0-1~bpo10+1","1.28.0-1~bpo10+2","1.29.0-1","1.3.0-1","1.3.0-1~bpo10+1","1.30.0-1","1.31.0-1","1.31.0-2","1.33.2-1","1.34.0-1","1.35.0-1","1.35.1-1","1.36.0-1","1.37.0-1","1.37.1-1","1.38.0-1","1.38.1-1","1.39.0-1","1.4.0-1","1.4.0~rc1-1","1.40.0-1","1.40.0-1~bpo10+1","1.40.0-1~bpo11+1","1.41.1-1","1.41.1-1~bpo10+1","1.41.1-1~bpo11+1","1.42.0-1","1.42.0-1~bpo10+1","1.42.0-1~bpo11+1","1.43.0-1","1.43.0-1~bpo10+1","1.43.0-1~bpo11+1","1.44.0-1","1.44.0-1~bpo10+1","1.44.0-1~bpo11+1","1.44.0-2","1.45.0-1","1.45.1-1","1.45.1-1~bpo10+1","1.45.1-1~bpo11+1","1.46.0-1","1.46.0-1~bpo10+1","1.46.0-1~bpo10+2","1.46.0-1~bpo11+1","1.46.0-1~bpo11+2","1.46.0-1~bpo11+3","1.47.0-1","1.47.0-2","1.47.0-2~bpo10+1","1.47.0-2~bpo11+1","1.47.1-1","1.47.1-1~bpo10+1","1.47.1-1~bpo11+1","1.48.0-1","1.48.0-1~bpo10+1","1.48.0-1~bpo11+1","1.49.0-1","1.49.0-1~bpo10+1","1.49.0-1~bpo10+2","1.49.0-1~bpo10+4","1.49.0-1~bpo11+1","1.49.0-1~bpo11+2","1.49.0-1~bpo11+3","1.49.2-1","1.5.0-1","1.5.0~rc1-1","1.5.1-1","1.5.1-1~bpo10+1","1.50.0-1","1.50.1-1","1.50.2-1","1.51.0-1","1.51.0-1~bpo10+1","1.51.0-1~bpo10+2","1.51.0-1~bpo10+3","1.51.0-1~bpo11+1","1.51.0-1~bpo11+2","1.52.0-1","1.52.0-1~bpo10+1","1.52.0-1~bpo11+1","1.53.0-1","1.53.0-1~bpo11+1","1.55.0-1","1.55.0-1~bpo11+1","1.55.0-2","1.56.0-1","1.57.1-1","1.57.1-1~bpo11+1","1.59.1-1","1.59.1-2","1.59.1-2~bpo11+1","1.6.0-1","1.6.1-1","1.6.1-1~bpo10+1","1.61.0-1","1.61.0-1~bpo11+1","1.61.0-1~bpo11+2","1.61.0-1~bpo11+3","1.61.0-2","1.61.0-3","1.61.1-1","1.63.0-1","1.63.0-1~bpo11+1","1.64.0-1","1.64.0-2","1.64.0-3","1.65.0-1","1.66.0-1","1.66.0-1~bpo11+1","1.66.0-2","1.68.0-1","1.68.0-1~bpo11+1","1.69.0-1","1.69.0-1~bpo11+1","1.7.0-1","1.7.0-2","1.7.1-1","1.7.2-1","1.7.2-1~bpo10+1","1.7.3-1","1.7.3-1~bpo10+1","1.70.1-1","1.70.1-1~bpo11+1","1.71.0-1","1.71.0-2","1.71.0-2~bpo11+1","1.72.0-1","1.72.0-1~bpo11+1","1.73.0-1","1.73.0-1~bpo11+1","1.74.0-1","1.74.0-1~bpo11+1","1.74.0-1~bpo11+2","1.77.0-1","1.78.0-1","1.78.0-1~bpo11+1","1.8.0-1","1.9.0-1","1.9.0-1~bpo10+1","1.9.1-1","1.9.1-1~bpo10+1","1.90.0-1","1.91.2-1","1.91.2-2","1.91.2-2~bpo12+1","1.92.0-1","1.92.0-2","1.92.0-3","1.92.0-3~bpo12+1","1.93.0-1","1.94.0-1","1.94.0-1~bpo12+1","1.95.0-1","1.95.0-1~bpo12+1","1.95.1-1","1.95.1-1~bpo12+1","1.97.0-1","1.99.0-1","1.99.0-2","1.99.0-3"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-61672.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}