Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied service. This vulnerability is fixed in 1.152.1.
References
| Link | Resource |
|---|---|
| https://github.com/element-hq/synapse/security/advisories/GHSA-8q93-326v-3m7g | Mitigation Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-05-28 17:16
Updated : 2026-06-17 10:51
NVD link : CVE-2026-45078
Mitre link : CVE-2026-45078
CVE.ORG link : CVE-2026-45078
JSON object : View
Products Affected
element
- synapse
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
