Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6qf2-7x63-mm6v | Synapse pagination Denial of Service |
Thu, 04 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Element
Element synapse |
|
| CPEs | cpe:2.3:a:element:synapse:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Element
Element synapse |
|
| Metrics |
cvssV3_1
|
Tue, 02 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Element-hq
Element-hq synapse |
|
| Vendors & Products |
Element-hq
Element-hq synapse |
Thu, 28 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full history to paginating clients. Clients could therefore fail to display room history. This vulnerability is fixed in 1.152.1. | |
| Title | Synapse pagination denial of service | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-02T14:51:34.553Z
Reserved: 2026-05-08T18:45:10.096Z
Link: CVE-2026-45076
Updated: 2026-06-02T14:51:26.936Z
Status : Analyzed
Published: 2026-05-28T17:16:31.590
Modified: 2026-06-04T18:04:26.643
Link: CVE-2026-45076
No data.
OpenCVE Enrichment
Updated: 2026-05-28T19:00:16Z
Github GHSA