Room Event Manipulation in Synapse by Element HQ
CVE-2026-45076
5.1MEDIUM
What is CVE-2026-45076?
Synapse, an open-source Matrix homeserver implementation by Element HQ, has a vulnerability affecting federated rooms. Malicious homeservers can craft specific room events that prevent Synapse from delivering complete room history to clients. As a result, users may experience incomplete or missing room history during pagination. This issue has been addressed in version 1.152.1 of Synapse.
Affected Version(s)
synapse < 1.152.1
