CVE-2026-45076

EUVD-2026-32934
Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full history to paginating clients. Clients could therefore fail to display room history. This vulnerability is fixed in 1.152.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.7 LOW
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 29.57%
Affected Products (NVD)
VendorProductVersion
elementsynapse
𝑥
< 1.152.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
matrix-synapse
sid
1.152.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
matrix-synapse
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
dne
resolute
dne