CVE-2024-51750

MEDIUM

Element Web < 1.11.85 - Denial of Service via Invalid Federation Messages

Title source: llm
STIX 2.1

Description

Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over federation which can prevent Element Web and Desktop from rendering single messages or the entire room containing them. This was patched in Element Web and Desktop 1.11.85.

Scores

CVSS v3 5.0
EPSS 0.0048
EPSS Percentile 37.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-248
Status published
Products (1)
element-hq/element-web < 1.11.85
Published Nov 12, 2024
Tracked Since Feb 18, 2026