CVE-2026-45078

Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied service. This vulnerability is fixed in 1.152.1.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:element:synapse:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-28 17:16

Updated : 2026-06-17 10:51


NVD link : CVE-2026-45078

Mitre link : CVE-2026-45078

CVE.ORG link : CVE-2026-45078


JSON object : View

Products Affected

element

  • synapse
CWE
CWE-770

Allocation of Resources Without Limits or Throttling