Improper Check for Unusual or Exceptional Conditions in Synapse - CVE-2026-45076

 

Improper Check for Unusual or Exceptional Conditions in Synapse - CVE-2026-45076

Published: May 12, 2026


Vulnerability identifier: #VU131158
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-45076
CWE-ID: CWE-754
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper handling of crafted room events in pagination in federated room history pagination when processing room events from federated homeservers. A remote user can send specially crafted room events to cause a denial of service.

The issue can prevent paginating clients from receiving full room history and may cause clients to fail to display room history.


Affected software

Synapse

How to mitigate CVE-2026-45076

Install security update from vendor's website.

Synapse - update to 1.152.1

External References

Related Security Bulletins