Skip to content

chore: bump Synapse from 1.128.0 to 1.149.1 (security)#68

Closed
helix-nine wants to merge 1 commit intomasterfrom
upstream/1.149.1
Closed

chore: bump Synapse from 1.128.0 to 1.149.1 (security)#68
helix-nine wants to merge 1 commit intomasterfrom
upstream/1.149.1

Conversation

@helix-nine
Copy link

Summary

Bumps upstream Synapse from v1.128.0 to v1.149.1 (21 minor versions). This is a security update.

🚨 Security

  • CVE-2026-24044 (v1.147.1): Blocks federation requests using a known insecure signing key. All deployments should upgrade.

Key Changes

  • New enable_local_media_storage config option
  • Stabilized MSC4312 OAuth UIA for cross-signing reset
  • MSC4354 Sticky Event metadata, MSC4388 secure QR sign-in
  • Fixed restricted v12 room joins
  • Fixed memory leak from stopped looping calls
  • Reactor tick time optimizations, Rust HTTP client improvements

Breaking Changes

  • Removed deprecated MSC2697 (dehydrated devices) and MSC3244

Files Changed

  • Dockerfile:3 — Base image tag v1.128.0v1.149.1
  • manifest.yaml:3 — Package version 1.128.01.149.1
  • manifest.yaml — Updated release notes

Upstream Changelog

element-hq/synapse@v1.128.0...v1.149.1

@MattDHill MattDHill closed this Mar 14, 2026
@MattDHill MattDHill deleted the upstream/1.149.1 branch March 14, 2026 18:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants