CVE-2026-45076
EPSS 0.08%Synapse pagination Denial of Service
發布日:2026/5/14修改日:2026/5/29
描述
Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full history to paginating clients. Clients could therefore fail to display room history. This vulnerability is fixed in 1.152.1.
受影響套件(2)
- Debian/matrix-synapsefrom 0, < 1.152.1-1
- PyPI/matrix-synapsefrom 0, < 1.152.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |