CVE-2026-45078

Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied service. This vulnerability is fixed in 1.152.1.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:element:synapse:*:*:*:*:*:*:*:*

History

03 Jun 2026, 02:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://github.com/element-hq/synapse/security/advisories/GHSA-8q93-326v-3m7g - () https://github.com/element-hq/synapse/security/advisories/GHSA-8q93-326v-3m7g - Mitigation, Vendor Advisory
CPE cpe:2.3:a:element:synapse:*:*:*:*:*:*:*:*
First Time Element synapse
Element

28 May 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 17:16

Updated : 2026-06-03 02:15


NVD link : CVE-2026-45078

Mitre link : CVE-2026-45078

CVE.ORG link : CVE-2026-45078


JSON object : View

Products Affected

element

  • synapse
CWE
CWE-770

Allocation of Resources Without Limits or Throttling