{"id":"CVE-2023-32323","aliases":["GHSA-f3wc-3vxv-xmvr","PYSEC-2023-67"],"url":"https://o3.security/vulnerability/CVE-2023-32323","summary":"Synapse Outgoing federation to specific hosts can be disabled by sending malicious invites","details":"Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. A malicious user on a Synapse homeserver X with permission to create certain state events can disable outbound federation from X to an arbitrary homeserver Y. Synapse instances with federation disabled are not affected. In versions of Synapse up to and including 1.73, Synapse did not limit the size of `invite_room_state`, meaning that it was possible to create an arbitrarily large invite event. Synapse 1.74 refuses to create oversized `invite_room_state` fields. Server operators should upgrade to Synapse 1.74 or newer urgently.","published":"2023-05-26T13:32:01.632Z","modified":"2026-08-12T03:51:12.157402210Z","cvss":{"score":5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"matrix-synapse","fixedVersion":"1.74.0"}],"fix":{"url":"https://github.com/matrix-org/synapse/pull/14642","label":"matrix-org/synapse#14642"},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UJIJRP5ZH6B3KGFLHCAKR2IX2Y4Z25QD/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/32xxx/CVE-2023-32323.json"},{"type":"ADVISORY","url":"https://github.com/matrix-org/synapse/security/advisories/GHSA-f3wc-3vxv-xmvr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-32323"},{"type":"REPORT","url":"https://github.com/matrix-org/synapse/issues/14492"},{"type":"FIX","url":"https://github.com/matrix-org/synapse/pull/14642"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:12.157402210Z"}}