关键漏洞信息 漏洞标题 Invalid device keys degrade federation functionality 严重性 High CVE ID CVE-2025-61672 影响版本 <1.138.3, =1.139.0 修复版本 1.139.1, 1.139.2, 1.138.3, 1.138.4 描述 Impact: Lack of validation for device keys in Synapse before 1.138.3 and in Synapse 1.139.0 allow an attacker registered on the victim homeserver to degrade federation functionality, unpredictably breaking outbound federation to other homeservers. 修复措施 Patches: Patched in Synapse 1.138.3, 1.138.4, 1.139.1, and 1.139.2. Note: Even though 1.138.3 and 1.139.1 fix the vulnerability, they inadvertently introduced an unrelated regression. For this reason, we recommend skipping these releases and upgrading straight to 1.138.4 and 1.139.2. 绕过方法 Workarounds: The vulnerability can only be exploited by users registered on the victim homeserver. 弱点 CWE-1287 发现者 dkasak