CVE-2026-45076: Synapse pagination Denial of Service
(updated )
In federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full history to paginating clients.
Clients could therefore fail to display room history.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-45076 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →