Element Synapse是Element开源的一个开源 Matrix 家庭服务器实现。 Element Synapse 1.127.0及之前版本存在输入验证错误漏洞,该漏洞源于恶意服务器可阻止与其他服务器联合。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| element-hq | synapse | < 1.127.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited in the wild. | https://github.com/ui-bootstrap/CVE-2025-30355 | POC Details |
No comments yet