← back
CVE-2026-45078

Synapse CPU starvation (Denial of Service)

CVSS 6.8 MEDIUMEPSS 0.1%CWE-770
Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied service. This vulnerability is fixed in 1.152.1.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected products
element-hq · synapse

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →