Denial of Service Vulnerability in Nanobot by HKUDS
CVE-2026-49140

5.3MEDIUM

Key Information:

Vendor

Hkuds

Status
Vendor
CVE Published:
1 June 2026

What is CVE-2026-49140?

Prior to version 0.2.1, Nanobot is exposed to a denial of service vulnerability associated with the Matrix channel media download handler. Authenticated room members can exploit this vulnerability by sending media events that lack or incorrectly specify size metadata. This exploitation allows attackers to initiate multiple concurrent media download requests that trigger excessive consumption of process memory and bandwidth. As these downloads fully materialize before rejection, the server's resources become severely depleted, resulting in service degradation. It is crucial for users of Nanobot to upgrade to version 0.2.1 or later to mitigate this risk.

Affected Version(s)

nanobot 0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Chia Min Jun Lennon
.