Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8q93-326v-3m7g

Опубликовано: 14 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 5.5

Описание

Synapse CPU starvation (Denial of Service)

Impact

Local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied service.

Homeservers that trust all their local users are not at risk.

Patches

Update to Synapse 1.152.1 or later.

Workarounds

If Synapse is deployed behind a reverse proxy, the reverse proxy could be configured to limit the rate of user requests, preventing or increasing the difficulty of the attack.

Identifiers

  • ELEMENTSEC-2026-1706

For more information

If you have any questions or comments about this advisory, please email us at security at element.io.

Пакеты

Наименование

matrix-synapse

pip
Затронутые версииВерсия исправления

< 1.152.1

1.152.1

EPSS

Процентиль: 3%
0.00128
Низкий

7.1 High

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-400
CWE-770

Связанные уязвимости

CVSS3: 5.5
ubuntu
3 месяца назад

Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied service. This vulnerability is fixed in 1.152.1.

CVSS3: 5.5
nvd
3 месяца назад

Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied service. This vulnerability is fixed in 1.152.1.

CVSS3: 5.5
debian
3 месяца назад

Synapse is an open source Matrix homeserver implementation. Prior to 1 ...

EPSS

Процентиль: 3%
0.00128
Низкий

7.1 High

CVSS4

5.5 Medium

CVSS3

Дефекты

CWE-400
CWE-770