PatchSiren

element-hq CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM element-hq CVE published 2026-08-21

CVE-2026-55850

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T19:17:04.230Z and has not been modified since then. Element Web, a Matrix web client built using the Matrix React SDK, had a vulnerability in its EmbeddedPage component prior to version 1.12.22. This vulnerability allowed a malicious homeserver to provide crafted HTML that Element Web rendered on [truncated]

MEDIUM element-hq CVE published 2026-05-28

CVE-2026-45078

CVE-2026-45078 is a medium-severity denial-of-service vulnerability in Synapse, the open-source Matrix homeserver implementation maintained by Element. Published on 2026-05-28, this vulnerability allows local authenticated users to trigger CPU resource exhaustion, causing other requests to fail and denying service to other users. The attack vector is local (AV:L) with low attack complexity (AC:L) and low [truncated]

MEDIUM element-hq CVE published 2026-05-28

CVE-2026-45076

CVE-2026-45076 is a medium-severity vulnerability in Synapse, an open-source Matrix homeserver implementation. The issue, published on 2026-05-28, affects versions prior to 1.152.1. In federated rooms, malicious homeservers can craft room events that prevent Synapse from providing complete history to paginating clients, potentially causing clients to fail to display room history. The vulnerability is clas [truncated]