{"id":"CVE-2022-31152","aliases":["GHSA-jhjh-776m-4765","PYSEC-2022-262"],"url":"https://o3.security/vulnerability/CVE-2022-31152","summary":"Synapse vulnerable to denial of service (DoS) due to incorrect application of event authorization rules","details":"### Impact\n\nThe Matrix specification specifies a list of [event authorization rules](https://spec.matrix.org/v1.3/rooms/v10/#authorization-rules) which must be checked when determining if an event should be accepted into a room.\n\nIn versions of Synapse up to and including v1.61, some of these rules are not correctly applied. An attacker could craft events which would be accepted by Synapse but not a spec-conformant server, potentially causing divergence in the room state between servers.\n\n### Patches\n\nAdministrators of homeservers with federation enabled are advised to upgrade to v1.62.0 or higher.\n\n### Workarounds\n\n * Federation can be disabled by setting [`federation_domain_whitelist`](https://matrix-org.github.io/synapse/latest/usage/configuration/config_documentation.html#federation_domain_whitelist) to an empty list (`[]`).\n\n### References\n\n * https://github.com/matrix-org/synapse/pull/13087\n * https://github.com/matrix-org/synapse/pull/13088\n\n### For more information\n\nIf you have any questions or comments about this advisory, e-mail us at [security@matrix.org](mailto:security@matrix.org).","published":"2022-09-02T20:00:16Z","modified":"2026-08-12T03:51:41.473247445Z","cvss":{"score":6.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H"},"epss":{"score":0.00957,"percentile":0.5826,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"matrix-synapse","fixedVersion":"1.62.0rc1"}],"fix":{"url":"https://github.com/matrix-org/synapse/pull/13087","label":"matrix-org/synapse#13087"},"references":[{"type":"WEB","url":"https://github.com/matrix-org/synapse/releases/tag/v1.62.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/31xxx/CVE-2022-31152.json"},{"type":"ADVISORY","url":"https://github.com/matrix-org/synapse/security/advisories/GHSA-jhjh-776m-4765"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31152"},{"type":"FIX","url":"https://github.com/matrix-org/synapse/pull/13087"},{"type":"FIX","url":"https://github.com/matrix-org/synapse/pull/13088"},{"type":"WEB","url":"https://github.com/matrix-org/synapse/commit/d4b1c0d800eaa83c4d56a9cf17881ad362b9194b"},{"type":"WEB","url":"https://github.com/matrix-org/synapse/commit/e16ea87d0f8c4c30cad36f85488eb1f647e640b0"},{"type":"PACKAGE","url":"https://github.com/matrix-org/synapse"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/matrix-synapse/PYSEC-2022-262.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:41.473247445Z"}}