Intel

AIKIDO-2026-304894

matrix-synapse is vulnerable to Spoofing

SpoofingGHSA-rgv2-84w7-5j9p Published 3 days ago

75

High Risk

This Affects:

PYTHONmatrix-synapse
0.0.1 - 1.157.1
Fixed in 1.157.2
Are you affected? Scan for Free

TL;DR

Synapse accepts to-device messages from remote homeservers without verifying that the message sender belongs to the originating server. A malicious federated homeserver can spoof the sender field so that a to-device message appears to have come from a different homeserver. This allows impersonation of users on other servers in to-device traffic. The fix validates the message origin against the claimed sender.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your homeserver participates in open federation.

Background info

matrix-synapse is vulnerable to Spoofing in versions 0.0.1 - 1.157.1.

How to fix this

Upgrade the matrix-synapse library to the patch version.