Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full history to paginating clients. Clients could therefore fail to display room history. This vulnerability is fixed in 1.152.1.
References
| Link | Resource |
|---|---|
| https://github.com/element-hq/synapse/security/advisories/GHSA-6qf2-7x63-mm6v | Vendor Advisory |
Configurations
History
04 Jun 2026, 18:04
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:element:synapse:*:*:*:*:*:*:*:* | |
| References | () https://github.com/element-hq/synapse/security/advisories/GHSA-6qf2-7x63-mm6v - Vendor Advisory | |
| First Time |
Element synapse
Element |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 2.7 |
28 May 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-28 17:16
Updated : 2026-06-04 18:04
NVD link : CVE-2026-45076
Mitre link : CVE-2026-45076
CVE.ORG link : CVE-2026-45076
JSON object : View
Products Affected
element
- synapse
CWE
CWE-20
Improper Input Validation
