Resource exhaustion in Synapse - CVE-2026-45078
Published: May 12, 2026
Synapse
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in request processing when handling authenticated user requests. A local user can send requests that starve other requests of CPU to cause a denial of service.
Homeservers that trust all their local users are not at risk.