QSearchQSearch

CVE-2026-45078

5.5 MEDIUM

Synapse is an open source Matrix homeserver implementation

Published: 2026-05-28 · Last updated: 2026-06-03

Severity and scoring

CVSS
5.5 MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE
CWE-770

Affected products

VendorProduct
elementsynapse

Description

Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied service. This vulnerability is fixed in 1.152.1.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-45076 Synapse is an open source Matrix homeserver implementation (2.7 LOW)

Same CWE

  • CVE-2026-53460 ImageMagick is free and open-source software used for editing and manipulating digital images (7.5 HIGH)
  • CVE-2026-46702 Russh is a Rust SSH client & server library (7.5 HIGH)
  • CVE-2026-46673 Russh is a Rust SSH client & server library (7.5 HIGH)
  • CVE-2026-45031 ImageMagick is free and open-source software used for editing and manipulating digital images (5.3 MEDIUM)
  • CVE-2026-10740 Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a... (5.3 MEDIUM)