CVE-2026-49140 Details
Description
Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel media download handler that allows authenticated room members to exhaust process memory and bandwidth by sending media events with missing or invalid size metadata. Attackers can send multiple concurrent Matrix media events with omitted or invalid declared sizes to trigger simultaneous large media downloads that fully materialize response bodies before post-download rejection, consuming process resources until service degradation occurs.
A denial-of-service vulnerability has been identified in Nanobot versions prior to 0.2.1. The issue resides in the Matrix channel media download handler, where authenticated room members can exploit missing or invalid size metadata in media events. This exploitation leads to excessive consumption of process memory and bandwidth. Attackers can send multiple concurrent media events with omitted or incorrect size declarations, causing simultaneous large media downloads. These downloads fully complete before being rejected, allowing the exploitation of process resources and resulting in service degradation.
Users can update to Nanobot version 0.2.1 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 1, 2026CISA-ADP
Assessed Jun 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/HKUDS/nanobot/pull/4106 | CISA-ADP | Issue TrackingVendor |
| https://github.com/HKUDS/nanobot/commit/1d4000560dfff1acb83f5c5ca8ef3ab1f092bd14 | [email protected] | Source CodeVendor |
| https://github.com/HKUDS/nanobot/pull/4106 | [email protected] | Issue TrackingVendor |
| https://github.com/HKUDS/nanobot/releases/tag/v0.2.1 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/nanobot-denial-of-service-via-matrix-media-download-handler | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Nanobot | < 0.2.1 (semver) |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | New CVE Received | [email protected] |
Volerion