CVE-2025-30355
Synapse vulnerable to federation denial of service via malformed events
7.1
HIGH
CVSS 3.1
EPSS 1.2%
描述
Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited in the wild and has been fixed in Synapse v1.127.1. No known workarounds are available.
如何修補 CVE-2025-30355
要修補 CVE-2025-30355,請將受影響套件升級到下列已修補版本。
- —升級至 1.127.1 或更新版本
- —升級至 1.127.1 或更新版本
CVE-2025-30355 正在被利用嗎?
低 — EPSS 為 1.2%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 1.127.1
- from 0, < 1.127.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H |