PYSEC-2026-1611
Synapse allows a a malformed invite to break the invitee's `/sync`
Quick fix
PYSEC-2026-1611 — matrix-synapse: upgrade to the fixed version with the command below.
pip install --upgrade 'matrix-synapse>=1.120.1'Details
### Impact
Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious server to send a specially crafted invite that disrupts the invited user's `/sync` functionality.
### Patches
Synapse 1.120.1 rejects such invalid invites received over federation and restores the ability to sync for affected users.
### Workarounds
Server administrators can disable federation from untrusted servers.
### For more information
If you have any questions or comments about this advisory, please email us at [security at element.io](mailto:security@element.io).
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.120.1pip install --upgrade 'matrix-synapse>=1.120.1'