PT-2026-45562 · Hkuds+1 · Nanobot

·

CVE-2026-49140

·

Published

2026-06-01

·

Updated

2026-07-22

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nanobot versions prior to 0.2.1
Description A denial of service issue exists in the Matrix channel media download handler. Authenticated room members can exhaust process memory and bandwidth by sending media events that lack or contain invalid size metadata. By sending multiple concurrent Matrix media events with omitted or invalid declared sizes, an attacker can trigger simultaneous large media downloads. These downloads fully materialize response bodies before they are rejected post-download, consuming system resources until service degradation occurs.
Recommendations Update Nanobot to version 0.2.1 or later.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49140

Affected Products

Nanobot