Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel media download handler that allows authenticated room members to exhaust process memory and bandwidth by sending media events with missing or invalid size metadata. Attackers can send multiple concurrent Matrix media events with omitted or invalid declared sizes to trigger simultaneous large media downloads that fully materialize response bodies before post-download rejection, consuming process resources until service degradation occurs.
Metrics
Affected Vendors & Products
References
History
Mon, 01 Jun 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hkuds
Hkuds nanobot |
|
| Vendors & Products |
Hkuds
Hkuds nanobot |
Mon, 01 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel media download handler that allows authenticated room members to exhaust process memory and bandwidth by sending media events with missing or invalid size metadata. Attackers can send multiple concurrent Matrix media events with omitted or invalid declared sizes to trigger simultaneous large media downloads that fully materialize response bodies before post-download rejection, consuming process resources until service degradation occurs. | |
| Title | Nanobot < 0.2.1 Denial of Service via Matrix Media Download Handler | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-01T19:54:53.921Z
Reserved: 2026-05-27T17:40:12.739Z
Link: CVE-2026-49140
No data.
Status : Received
Published: 2026-06-01T21:16:47.070
Modified: 2026-06-01T21:16:47.070
Link: CVE-2026-49140
No data.
OpenCVE Enrichment
Updated: 2026-06-01T21:30:26Z