CVE-2026-49140

Source
https://cve.org/CVERecord?id=CVE-2026-49140
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49140.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-49140
Published
2026-06-01T19:54:53.921Z
Modified
2026-07-16T03:31:10.110051861Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Nanobot < 0.2.1 Denial of Service via Matrix Media Download Handler
Details

Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel media download handler that allows authenticated room members to exhaust process memory and bandwidth by sending media events with missing or invalid size metadata. Attackers can send multiple concurrent Matrix media events with omitted or invalid declared sizes to trigger simultaneous large media downloads that fully materialize response bodies before post-download rejection, consuming process resources until service degradation occurs.

Database specific
{
    "cwe_ids": [
        "CWE-770"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49140.json",
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/hkuds/nanobot

Affected ranges

Type
GIT
Repo
https://github.com/hkuds/nanobot
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.2.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.1.3.post4
v0.1.3.post5
v0.1.3.post6
v0.1.4
v0.1.4.post1
v0.1.4.post2
v0.1.4.post3
v0.1.4.post4
v0.1.4.post6
v0.1.5
v0.1.5.post1
v0.1.5.post2
v0.1.5.post3
v0.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49140.json"