Skip to content

Refuse requests and events signed by banned signing keys#19459

Merged
sandhose merged 2 commits intorelease-v1.147from
quenting/key-ban-ELEMENTSEC-2025-1670
Feb 12, 2026
Merged

Refuse requests and events signed by banned signing keys#19459
sandhose merged 2 commits intorelease-v1.147from
quenting/key-ban-ELEMENTSEC-2025-1670

Conversation

@sandhose
Copy link
Copy Markdown
Member

@sandhose sandhose commented Feb 12, 2026

@sandhose sandhose requested a review from a team as a code owner February 12, 2026 15:05
@sandhose sandhose changed the base branch from develop to release-v1.147 February 12, 2026 15:34
@sandhose sandhose merged commit be36242 into release-v1.147 Feb 12, 2026
43 of 46 checks passed
@sandhose sandhose deleted the quenting/key-ban-ELEMENTSEC-2025-1670 branch February 12, 2026 15:40
mcalinghee added a commit to tchapgouv/synapse that referenced this pull request Feb 16, 2026
- Block federation requests and events authenticated using a known insecure signing key. See [CVE-2026-24044](https://www.cve.org/CVERecord?id=CVE-2026-24044) / [ELEMENTSEC-2025-1670](GHSA-qwcj-h6m8-vp6q). ([\element-hq#19459](element-hq#19459))

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEE7qit+jwB/tnnqkQqItYrhFUnGfwFAmmN9ucACgkQItYrhFUn
# Gfxn0RAAphtPC/LnSaefBHgNNKN0cnFK6N9FvuvKyEkqKYQNNoCaAGW2NzmeFfcX
# lPKCZWaABgCQUTxQWf2ck2VlGe3SwcLTUwcIjnlVs8uYP8JiTek8743Czx8T88M1
# TlotLgnH93nNudXOCXAThYbktrOZZtJM1E7AWJLUfQcUFS30ZbEgCYAmCuJ60OgL
# jn80CKHQJxw9u1Hty1G9yN2j0gLjO4KRkSuQ7jc3ouG2Fx/HQZ8H1/zX/H4niClN
# Y5VAPp0V0VN9KKV1xJXayDQ25ytAqkZvOpBnMIhHmCEFKElio3BlpjnlajsGfIqW
# 6SKwmDczjrdKwbnOFtOFUzqs2LWm9RZOo8mrdDpb4uWiZ8ANnyffajrROzRGCI8d
# 8NeOJKYl9fHZrEtAiZYPBYJNOtmW/+CtxckfOkBKri4i8ryDsXS2iER7LrMc2tyd
# oZVVDLX2l74KLw4NziSxqheQVKFShSWBxuDb2AVk15BhoMZd7YcAP+VFtmf0ZtUD
# XBaGQ+oWA4C2a8WSVHPXezSwt78sKcILH1bL6ZzUUen0k8bavjxW0xb3Db4F00D1
# P/SXHdN18XYdsjYcpC1b1zuUUVLD5wXnVj2fKAWlierokD1Y3Q6G6NREI/L4G350
# asu+ejyQrJn3VKoFtGccfGdvNlp8BKxCvWNXA/cy5042HUuSJiY=
# =/PNG
# -----END PGP SIGNATURE-----
# gpg: Signature made Thu Feb 12 16:51:03 2026 CET
# gpg:                using RSA key EEA8ADFA3C01FED9E7AA442A22D62B84552719FC
# gpg: Can't check signature: No public key

# Conflicts:
#	.github/workflows/release-artifacts.yml
#	synapse/app/_base.py
mcalinghee added a commit to tchapgouv/synapse that referenced this pull request Feb 16, 2026
- Block federation requests and events authenticated using a known insecure signing key. See [CVE-2026-24044](https://www.cve.org/CVERecord?id=CVE-2026-24044) / [ELEMENTSEC-2025-1670](GHSA-qwcj-h6m8-vp6q). ([\element-hq#19459](element-hq#19459))

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEE7qit+jwB/tnnqkQqItYrhFUnGfwFAmmN9ucACgkQItYrhFUn
# Gfxn0RAAphtPC/LnSaefBHgNNKN0cnFK6N9FvuvKyEkqKYQNNoCaAGW2NzmeFfcX
# lPKCZWaABgCQUTxQWf2ck2VlGe3SwcLTUwcIjnlVs8uYP8JiTek8743Czx8T88M1
# TlotLgnH93nNudXOCXAThYbktrOZZtJM1E7AWJLUfQcUFS30ZbEgCYAmCuJ60OgL
# jn80CKHQJxw9u1Hty1G9yN2j0gLjO4KRkSuQ7jc3ouG2Fx/HQZ8H1/zX/H4niClN
# Y5VAPp0V0VN9KKV1xJXayDQ25ytAqkZvOpBnMIhHmCEFKElio3BlpjnlajsGfIqW
# 6SKwmDczjrdKwbnOFtOFUzqs2LWm9RZOo8mrdDpb4uWiZ8ANnyffajrROzRGCI8d
# 8NeOJKYl9fHZrEtAiZYPBYJNOtmW/+CtxckfOkBKri4i8ryDsXS2iER7LrMc2tyd
# oZVVDLX2l74KLw4NziSxqheQVKFShSWBxuDb2AVk15BhoMZd7YcAP+VFtmf0ZtUD
# XBaGQ+oWA4C2a8WSVHPXezSwt78sKcILH1bL6ZzUUen0k8bavjxW0xb3Db4F00D1
# P/SXHdN18XYdsjYcpC1b1zuUUVLD5wXnVj2fKAWlierokD1Y3Q6G6NREI/L4G350
# asu+ejyQrJn3VKoFtGccfGdvNlp8BKxCvWNXA/cy5042HUuSJiY=
# =/PNG
# -----END PGP SIGNATURE-----
# gpg: Signature made Thu Feb 12 16:51:03 2026 CET
# gpg:                using RSA key EEA8ADFA3C01FED9E7AA442A22D62B84552719FC
# gpg: Can't check signature: No public key

# Conflicts:
#	.github/workflows/release-artifacts.yml
#	synapse/app/_base.py
mcalinghee added a commit to tchapgouv/synapse that referenced this pull request Feb 16, 2026
- Block federation requests and events authenticated using a known insecure signing key. See [CVE-2026-24044](https://www.cve.org/CVERecord?id=CVE-2026-24044) / [ELEMENTSEC-2025-1670](GHSA-qwcj-h6m8-vp6q). ([\element-hq#19459](element-hq#19459))

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEE7qit+jwB/tnnqkQqItYrhFUnGfwFAmmN9ucACgkQItYrhFUn
# Gfxn0RAAphtPC/LnSaefBHgNNKN0cnFK6N9FvuvKyEkqKYQNNoCaAGW2NzmeFfcX
# lPKCZWaABgCQUTxQWf2ck2VlGe3SwcLTUwcIjnlVs8uYP8JiTek8743Czx8T88M1
# TlotLgnH93nNudXOCXAThYbktrOZZtJM1E7AWJLUfQcUFS30ZbEgCYAmCuJ60OgL
# jn80CKHQJxw9u1Hty1G9yN2j0gLjO4KRkSuQ7jc3ouG2Fx/HQZ8H1/zX/H4niClN
# Y5VAPp0V0VN9KKV1xJXayDQ25ytAqkZvOpBnMIhHmCEFKElio3BlpjnlajsGfIqW
# 6SKwmDczjrdKwbnOFtOFUzqs2LWm9RZOo8mrdDpb4uWiZ8ANnyffajrROzRGCI8d
# 8NeOJKYl9fHZrEtAiZYPBYJNOtmW/+CtxckfOkBKri4i8ryDsXS2iER7LrMc2tyd
# oZVVDLX2l74KLw4NziSxqheQVKFShSWBxuDb2AVk15BhoMZd7YcAP+VFtmf0ZtUD
# XBaGQ+oWA4C2a8WSVHPXezSwt78sKcILH1bL6ZzUUen0k8bavjxW0xb3Db4F00D1
# P/SXHdN18XYdsjYcpC1b1zuUUVLD5wXnVj2fKAWlierokD1Y3Q6G6NREI/L4G350
# asu+ejyQrJn3VKoFtGccfGdvNlp8BKxCvWNXA/cy5042HUuSJiY=
# =/PNG
# -----END PGP SIGNATURE-----
# gpg: Signature made Thu Feb 12 16:51:03 2026 CET
# gpg:                using RSA key EEA8ADFA3C01FED9E7AA442A22D62B84552719FC
# gpg: Can't check signature: No public key

# Conflicts:
#	.github/workflows/release-artifacts.yml
#	synapse/app/_base.py
mcalinghee added a commit to tchapgouv/synapse that referenced this pull request Feb 16, 2026
- Block federation requests and events authenticated using a known insecure signing key. See [CVE-2026-24044](https://www.cve.org/CVERecord?id=CVE-2026-24044) / [ELEMENTSEC-2025-1670](GHSA-qwcj-h6m8-vp6q). ([\element-hq#19459](element-hq#19459))

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEE7qit+jwB/tnnqkQqItYrhFUnGfwFAmmN9ucACgkQItYrhFUn
# Gfxn0RAAphtPC/LnSaefBHgNNKN0cnFK6N9FvuvKyEkqKYQNNoCaAGW2NzmeFfcX
# lPKCZWaABgCQUTxQWf2ck2VlGe3SwcLTUwcIjnlVs8uYP8JiTek8743Czx8T88M1
# TlotLgnH93nNudXOCXAThYbktrOZZtJM1E7AWJLUfQcUFS30ZbEgCYAmCuJ60OgL
# jn80CKHQJxw9u1Hty1G9yN2j0gLjO4KRkSuQ7jc3ouG2Fx/HQZ8H1/zX/H4niClN
# Y5VAPp0V0VN9KKV1xJXayDQ25ytAqkZvOpBnMIhHmCEFKElio3BlpjnlajsGfIqW
# 6SKwmDczjrdKwbnOFtOFUzqs2LWm9RZOo8mrdDpb4uWiZ8ANnyffajrROzRGCI8d
# 8NeOJKYl9fHZrEtAiZYPBYJNOtmW/+CtxckfOkBKri4i8ryDsXS2iER7LrMc2tyd
# oZVVDLX2l74KLw4NziSxqheQVKFShSWBxuDb2AVk15BhoMZd7YcAP+VFtmf0ZtUD
# XBaGQ+oWA4C2a8WSVHPXezSwt78sKcILH1bL6ZzUUen0k8bavjxW0xb3Db4F00D1
# P/SXHdN18XYdsjYcpC1b1zuUUVLD5wXnVj2fKAWlierokD1Y3Q6G6NREI/L4G350
# asu+ejyQrJn3VKoFtGccfGdvNlp8BKxCvWNXA/cy5042HUuSJiY=
# =/PNG
# -----END PGP SIGNATURE-----
# gpg: Signature made Thu Feb 12 16:51:03 2026 CET
# gpg:                using RSA key EEA8ADFA3C01FED9E7AA442A22D62B84552719FC
# gpg: Can't check signature: No public key

# Conflicts:
#	.github/workflows/release-artifacts.yml
#	synapse/app/_base.py
mcalinghee added a commit to tchapgouv/synapse that referenced this pull request Feb 16, 2026
- Block federation requests and events authenticated using a known insecure signing key. See [CVE-2026-24044](https://www.cve.org/CVERecord?id=CVE-2026-24044) / [ELEMENTSEC-2025-1670](GHSA-qwcj-h6m8-vp6q). ([\element-hq#19459](element-hq#19459))

# -----BEGIN PGP SIGNATURE-----
#
# iQIzBAABCgAdFiEE7qit+jwB/tnnqkQqItYrhFUnGfwFAmmN9ucACgkQItYrhFUn
# Gfxn0RAAphtPC/LnSaefBHgNNKN0cnFK6N9FvuvKyEkqKYQNNoCaAGW2NzmeFfcX
# lPKCZWaABgCQUTxQWf2ck2VlGe3SwcLTUwcIjnlVs8uYP8JiTek8743Czx8T88M1
# TlotLgnH93nNudXOCXAThYbktrOZZtJM1E7AWJLUfQcUFS30ZbEgCYAmCuJ60OgL
# jn80CKHQJxw9u1Hty1G9yN2j0gLjO4KRkSuQ7jc3ouG2Fx/HQZ8H1/zX/H4niClN
# Y5VAPp0V0VN9KKV1xJXayDQ25ytAqkZvOpBnMIhHmCEFKElio3BlpjnlajsGfIqW
# 6SKwmDczjrdKwbnOFtOFUzqs2LWm9RZOo8mrdDpb4uWiZ8ANnyffajrROzRGCI8d
# 8NeOJKYl9fHZrEtAiZYPBYJNOtmW/+CtxckfOkBKri4i8ryDsXS2iER7LrMc2tyd
# oZVVDLX2l74KLw4NziSxqheQVKFShSWBxuDb2AVk15BhoMZd7YcAP+VFtmf0ZtUD
# XBaGQ+oWA4C2a8WSVHPXezSwt78sKcILH1bL6ZzUUen0k8bavjxW0xb3Db4F00D1
# P/SXHdN18XYdsjYcpC1b1zuUUVLD5wXnVj2fKAWlierokD1Y3Q6G6NREI/L4G350
# asu+ejyQrJn3VKoFtGccfGdvNlp8BKxCvWNXA/cy5042HUuSJiY=
# =/PNG
# -----END PGP SIGNATURE-----
# gpg: Signature made Thu Feb 12 16:51:03 2026 CET
# gpg:                using RSA key EEA8ADFA3C01FED9E7AA442A22D62B84552719FC
# gpg: Can't check signature: No public key

# Conflicts:
#	.github/workflows/release-artifacts.yml
#	synapse/app/_base.py
github-merge-queue bot pushed a commit to famedly/synapse that referenced this pull request Feb 18, 2026
# Famedly Synapse Release v1.147.1_1

depends on: famedly/complement#11

## Famedly additions for v1.146.0_1

None

### Notes for Famedly:

- Disallow requests to the health endpoint from containing trailing path
characters.
([\#19405](element-hq/synapse#19405))
- Block federation requests and events authenticated using a known
insecure signing key. See
[CVE-2026-24044](https://www.cve.org/CVERecord?id=CVE-2026-24044) /
[ELEMENTSEC-2025-1670](GHSA-qwcj-h6m8-vp6q).
([\#19459](element-hq/synapse#19459))
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants