Denial of Service Vulnerability in Synapse Matrix Homeserver by Element
CVE-2026-45078

6.8MEDIUM

Key Information:

Vendor

Element-hq

Status
Vendor
CVE Published:
28 May 2026

What is CVE-2026-45078?

The Synapse Matrix homeserver by Element contains a vulnerability that allows local authenticated users to exploit the system, leading to a denial of service condition. These users can consume excessive CPU resources, resulting in other legitimate requests being unable to process. This disruption affects overall server performance, denying service to other users. The issue has been addressed in version 1.152.1, where necessary mitigations have been implemented to prevent this mode of attack.

Affected Version(s)

synapse < 1.152.1

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.