Vulnerability Bulletins

CVE-2026-45076

   
Affected software MATRIX SYNAPSE
 
Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full history to paginating clients. Clients could therefore fail to display room history. This vulnerability is fixed in 1.152.1.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-45076