CVE-2026-45078
published 2026-05-28CVE-2026-45078: Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.13%
2.9th percentile
Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied service. This vulnerability is fixed in 1.152.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | matrix-synapse | >= 0 < 1.152.1 | 1.152.1 |
| element-hq | synapse | < 1.152.1 | 1.152.1 |
| element | synapse | < 1.152.1 | 1.152.1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.06.8MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
element-hq synapse up to 1.152.0 allocation of resources (GHSA-8q93-326v-3m7g / Nessus ID 317950)
vuldb·2026-06-07·CVSS 5.5
CVE-2026-45078 [MEDIUM] element-hq synapse up to 1.152.0 allocation of resources (GHSA-8q93-326v-3m7g / Nessus ID 317950)
A vulnerability was found in element-hq synapse up to 1.152.0. It has been classified as problematic. This affects an unknown part. Performing a manipulation results in allocation of resources.
This vulnerability is cataloged as CVE-2026-45078. The attack must be initiated from a local position. There is no exploit available.
Upgrading the affected component is recommended.
GHSA
Synapse CPU starvation (Denial of Service)
ghsa·2026-05-14
CVE-2026-45078 [HIGH] CWE-400 Synapse CPU starvation (Denial of Service)
Synapse CPU starvation (Denial of Service)
### Impact
Local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied service.
Homeservers that trust all their local users are not at risk.
### Patches
Update to Synapse 1.152.1 or later.
### Workarounds
If Synapse is deployed behind a reverse proxy, the reverse proxy could be configured to limit the rate of user requests,
preventing or increasing the difficulty of the attack.
### Identifiers
- ELEMENTSEC-2026-1706
### For more information
If you have any questions or comments about this advisory, please email us at [security at element.io](mailto:[email protected]).
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-45078 matrix-synapse: Synapse: Denial of Service due to resource exhaustion by authenticated users [fedora-all]
bugzilla·2026-06-16·CVSS 5.5
CVE-2026-45078 [MEDIUM] CVE-2026-45078 matrix-synapse: Synapse: Denial of Service due to resource exhaustion by authenticated users [fedora-all]
CVE-2026-45078 matrix-synapse: Synapse: Denial of Service due to resource exhaustion by authenticated users [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-45078 synapse: Synapse: Denial of Service due to resource exhaustion by authenticated users [fedora-all]
bugzilla·2026-06-16·CVSS 5.5
CVE-2026-45078 [MEDIUM] CVE-2026-45078 synapse: Synapse: Denial of Service due to resource exhaustion by authenticated users [fedora-all]
CVE-2026-45078 synapse: Synapse: Denial of Service due to resource exhaustion by authenticated users [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This CVE entry has no relation with the rpm component referenced here.
Bugzilla
CVE-2026-45078 synapse: Synapse: Denial of Service due to resource exhaustion by authenticated users
bugzilla·2026-05-28·CVSS 5.5
CVE-2026-45078 [MEDIUM] CVE-2026-45078 synapse: Synapse: Denial of Service due to resource exhaustion by authenticated users
CVE-2026-45078 synapse: Synapse: Denial of Service due to resource exhaustion by authenticated users
Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied service. This vulnerability is fixed in 1.152.1.
2026-05-28
Published