Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8q93-326v-3m7g | Synapse CPU starvation (Denial of Service) |
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Element
Element synapse |
|
| CPEs | cpe:2.3:a:element:synapse:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Element
Element synapse |
|
| Metrics |
cvssV3_1
|
Fri, 29 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 28 May 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Element-hq
Element-hq synapse |
|
| Vendors & Products |
Element-hq
Element-hq synapse |
Thu, 28 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied service. This vulnerability is fixed in 1.152.1. | |
| Title | Synapse CPU starvation (Denial of Service) | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-29T15:31:44.793Z
Reserved: 2026-05-08T18:45:10.097Z
Link: CVE-2026-45078
Updated: 2026-05-29T15:31:41.450Z
Status : Analyzed
Published: 2026-05-28T17:16:31.750
Modified: 2026-06-03T02:15:33.060
Link: CVE-2026-45078
No data.
OpenCVE Enrichment
Updated: 2026-05-28T19:45:24Z
Github GHSA