VYPR
Vendor

Matrix Org

Products
30
CVEs
115
Across products
149
Status
Private

Products

30

Recent CVEs

115
View all 115 CVEs →
  • CVE-2024-10381CriOct 25, 2024
    risk 0.64cvss 9.8epss 0.01

    This vulnerability exists in Matrix Door Controller Cosec Vega FAXQ due to improper implementation of session management at the web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the vulnerable…

  • CVE-2021-44538CriDec 14, 2021
    risk 0.64cvss 9.8epss 0.02

    The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can…

  • CVE-2024-53863CriDec 3, 2024
    risk 0.59cvss 9.1epss 0.01

    Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option or processing a specially crafted request could trigger the decoding and thumbnail generation of uncommon image formats, potentially invoking external tools…

  • CVE-2022-39203HigSep 13, 2022
    risk 0.57cvss 8.8epss 0.01

    matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. Attackers can specify a specific string of characters, which would confuse the bridge into combining an attacker-owned channel and an existing channel, allowing them to grant themselves permissions in the…

  • CVE-2019-18835CriNov 8, 2019
    risk 0.57cvss 9.8epss 0.01

    Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers.

  • CVE-2023-38686CriAug 4, 2023
    risk 0.53cvss 9.3epss 0.00

    Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send emails using TLS, Sydent does not verify SMTP servers' certificates. This makes Sydent's emails vulnerable to interception via a man-in-the-middle (MITM) attack.…

  • CVE-2023-28427HigMar 28, 2023
    risk 0.53cvss 8.2epss 0.01

    matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability…

  • CVE-2023-28103HigMar 28, 2023
    risk 0.53cvss 8.2epss 0.01

    matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. In certain configurations, data sent by remote servers containing special strings in key locations could cause modifications of the `Object.prototype`, disrupting matrix-react-sdk functionality, causing denial…

  • CVE-2025-24024CriJan 21, 2025
    risk 0.52cvss 9.1epss 0.01

    Mjolnir is a moderation tool for Matrix. Mjolnir v1.9.0 responds to management commands from any room the bot is member of. This can allow users who aren't operators of the bot to use the bot's functions, including server administration components if enabled. Version 1.9.1…

  • CVE-2022-29166HigMay 5, 2022
    risk 0.52cvss 8.0epss 0.01

    matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate a Matrix user into executing IRC commands by having them reply to a maliciously crafted message. The vulnerability has been patched in matrix-appservice-irc…

  • CVE-2024-47824HigOct 15, 2024
    risk 0.50cvss epss 0.01

    matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starting in version 3.18.0 and before 3.102.0, matrix-react-sdk allows a malicious homeserver to potentially steal message keys for a room when a user invites…

  • CVE-2024-47080HigOct 15, 2024
    risk 0.50cvss epss 0.01

    matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 through 34.7.0, the method `MatrixClient.sendSharedHistoryKeys` is vulnerable to interception by malicious homeservers. The method was introduced by MSC3061)…

  • CVE-2018-16515HigSep 18, 2018
    risk 0.50cvss 8.8epss 0.02

    Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.

  • CVE-2024-52805HigDec 3, 2024
    risk 0.49cvss 7.5epss 0.01

    Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks.…

  • CVE-2024-38429HigJul 30, 2024
    risk 0.49cvss 7.5epss 0.00

    Matrix Tafnit v8 -  CWE-552: Files or Directories Accessible to External Parties

  • CVE-2022-39252HigSep 29, 2022
    risk 0.49cvss 8.6epss 0.01

    matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library. Prior to version 0.6, when a user requests a room key from their devices, the software correctly remembers the request. When the user receives…

  • CVE-2022-39250HigSep 29, 2022
    risk 0.49cvss 8.6epss 0.01

    Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver could interfere with the verification flow between two users, injecting its own cross-signing user…

  • CVE-2022-39251HigSep 28, 2022
    risk 0.49cvss 8.6epss 0.01

    Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield.…

  • CVE-2022-39248HigSep 28, 2022
    risk 0.49cvss 8.6epss 0.01

    matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a…

  • CVE-2020-26890HigNov 24, 2020
    risk 0.49cvss 7.5epss 0.03

    Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing remote attackers to execute a denial of service attack against the federation and common Matrix clients. If such a malformed event…