diff --git a/CHANGES.rst b/CHANGES.rst
index 4047f50aa5de3268f636e5b9368a98a659b64d3f..08d11301e7b495f12e896e62843b330e25483bb7 100644
--- a/CHANGES.rst
+++ b/CHANGES.rst
@@ -1,3 +1,9 @@
+Changes in synapse v0.31.2 (2018-06-14)
+=======================================
+
+SECURITY UPDATE: Prevent unauthorised users from setting state events in a room
+when there is no ``m.room.power_levels`` event in force in the room. (PR #3397)
+
 Changes in synapse v0.31.1 (2018-06-08)
 =======================================