CVE-2026-45078

EUVD-2026-32935
Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied service. This vulnerability is fixed in 1.152.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 2.71%
Affected Products (NVD)
VendorProductVersion
elementsynapse
𝑥
< 1.152.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
matrix-synapse
sid
1.152.1-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
matrix-synapse
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
dne
resolute
dne