Resource exhaustion in Synapse - #VU139992
Published: July 29, 2026
Synapse
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in user-configured push rules when processing or loading push rules. A remote user can create an unbounded number of push rules with an unbounded total size to cause a denial of service.
Homeservers that trust all their local users are not affected.