Skip to main content

Vendor archive

matrix CVEs

Beta · best-effort

82 CVEs tagged to vendor matrix4 Critical, 30 High, 38 Medium, 10 Low, 0 Unrated.

CVE-2025-66622

Published Dec 9, 2025

matrix-sdk-base is the base component to build a Matrix client library. Versions 0.14.1 and prior are unable to handle responses that include custom m.room.join_rules values due t…

CVSS 1.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-30355

Published Mar 27, 2025

Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with ot…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27146

Published Feb 25, 2025

matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command exe…

CVSS 2.7 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-53863

Published Dec 3, 2024

Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option or processing a specially crafted request could trigger the…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52815

Published Dec 3, 2024

Synapse is an open-source Matrix homeserver. Synapse versions before 1.120.1 fail to properly validate invites received over federation. This vulnerability allows a malicious serv…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52805

Published Dec 3, 2024

Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond e…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37303

Published Dec 3, 2024

Synapse is an open-source Matrix homeserver. Synapse before version 1.106 allows, by design, unauthenticated remote participants to trigger a download and caching of remote media…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-37302

Published Dec 3, 2024

Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where an unauthenticated adversary can induce Synapse to download…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45193

Published Aug 22, 2024

An issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due to lack of validation criteria (does not ensure that S < n). This refers to th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45192

Published Aug 22, 2024

An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decoding group session keys. This refers to the libolm implementa…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45191

Published Aug 22, 2024

An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cache-timing attacks due to use of S-boxes. This is related to software that uses…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42369

Published Aug 20, 2024

matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. A malicious homeserver can craft a room or room structure such that the predecessors form a cycle. T…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-42347

Published Aug 6, 2024

matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client t…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-31208

Published Apr 23, 2024

Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted event…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43796

Published Oct 31, 2023

Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enum…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-45129

Published Oct 10, 2023

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance tempo…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-43656

Published Sep 27, 2023

matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. Instances that have enabled transformation functions (those that have `gen…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-42453

Published Sep 27, 2023

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users were able to forge read receipts for any event (if they knew the room ID and…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-41335

Published Sep 27, 2023

Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their passwords, the new credentials may be briefly held in the…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-38700

Published Aug 4, 2023

matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it was possible to craft an event such that it would leak part of a targeted message event from a…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-38691

Published Aug 4, 2023

matrix-appservice-bridge provides an API for setting up bridges. Starting in version 4.0.0 and prior to versions 8.1.2 and 9.0.1, a malicious Matrix server can use a foreign user'…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38690

Published Aug 4, 2023

matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with newlines which would not be properly parsed. This would me…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38686

Published Aug 4, 2023

Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send emails using TLS, Sydent does not verify SMTP servers' certifica…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-32683

Published Jun 6, 2023

Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. A discovered oEmbed or image URL can bypass the `url_preview_url_blacklist` setting potential…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-32682

Published Jun 6, 2023

Synapse is a Matrix protocol homeserver written in Python with the Twisted framework. In affected versions it may be possible for a deactivated user to login when using uncommon c…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 82 CVEsPage 1 of 4