Intel

AIKIDO-2026-562657

matrix-synapse is vulnerable to Improper Verification of Data Authenticity

Improper Verification of Data AuthenticityGHSA-cjh7-rcpx-xpf8 Published 3 days ago

71

High Risk

This Affects:

PYTHONmatrix-synapse
0.0.1 - 1.157.1
Fixed in 1.157.2
Are you affected? Scan for Free

TL;DR

When handling remote room joins, Synapse does not sufficiently verify tombstone and room-upgrade predecessor relationships. A malicious federated homeserver, in cooperation with or by tricking a local user, can cause a room alias to be redirected so its destination room changes. This lets an existing alias point users to an unintended, attacker-influenced room. The fix verifies tombstone and upgrade predecessors before accepting the relationship.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range, your homeserver participates in open federation, and a local authenticated user can be induced to join or cooperate with an untrusted federated room that abuses tombstone or room-upgrade predecessor relationships to redirect a room alias.

Background info

matrix-synapse is vulnerable to Improper Verification of Data Authenticity in versions 0.0.1 - 1.157.1.

How to fix this

Upgrade the matrix-synapse library to the patch version.