---
id: CVE-2026-45076
aliases:
  - GHSA-6qf2-7x63-mm6v
  - PYSEC-2026-194
title: Synapse pagination Denial of Service
summary: Synapse pagination Denial of Service
severity: medium
vendor: matrix-synapse
product: matrix-synapse
ecosystem: pip
affected:
  - matrix-synapse < 1.152.1
patched:
  - matrix-synapse 1.152.1
published: '2026-05-14'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:45.939755552Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-6qf2-7x63-mm6v'
references:
  - url: >-
      https://github.com/element-hq/synapse/security/advisories/GHSA-6qf2-7x63-mm6v
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45076'
  - url: 'https://github.com/element-hq/synapse'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/matrix-synapse/PYSEC-2026-194.yaml
tags:
  - osv
  - pip
epss: 0.00385
epssPercentile: 0.29706
ingestedAt: '2026-09-12T03:13:01.667Z'
---

## Overview

### Impact

In federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full history to paginating clients.

Clients could therefore fail to display room history.

### Patches

Update to Synapse 1.152.1 or later.

### Workarounds

There are no known workarounds for this issue.

### Identifiers

- ELEMENTSEC-2025-1636

### For more information

If you have any questions or comments about this advisory, please email us at [security at element.io](mailto:security@element.io).

## Affected packages

- `matrix-synapse < 1.152.1`

## Remediation

Upgrade to a patched release:

- `matrix-synapse 1.152.1`
