PT-2026-45562 · Hkuds+1 · Nanobot
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Nanobot versions prior to 0.2.1
Description
A denial of service issue exists in the Matrix channel media download handler. Authenticated room members can exhaust process memory and bandwidth by sending media events that lack or contain invalid size metadata. By sending multiple concurrent Matrix media events with omitted or invalid declared sizes, an attacker can trigger simultaneous large media downloads. These downloads fully materialize response bodies before they are rejected post-download, consuming system resources until service degradation occurs.
Recommendations
Update Nanobot to version 0.2.1 or later.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nanobot