VYPR

Vendor CVEs

Matrix Org

All CVEs

115 total · sorted by risk
  • CVE-2024-10381CriOct 25, 2024
    risk 0.64cvss 9.8epss 0.01

    This vulnerability exists in Matrix Door Controller Cosec Vega FAXQ due to improper implementation of session management at the web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the vulnerable…

  • CVE-2021-44538CriDec 14, 2021
    risk 0.64cvss 9.8epss 0.02

    The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can…

  • CVE-2024-53863CriDec 3, 2024
    risk 0.59cvss 9.1epss 0.01

    Synapse is an open-source Matrix homeserver. In Synapse versions before 1.120.1, enabling the dynamic_thumbnails option or processing a specially crafted request could trigger the decoding and thumbnail generation of uncommon image formats, potentially invoking external tools…

  • CVE-2022-39203HigSep 13, 2022
    risk 0.57cvss 8.8epss 0.01

    matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. Attackers can specify a specific string of characters, which would confuse the bridge into combining an attacker-owned channel and an existing channel, allowing them to grant themselves permissions in the…

  • CVE-2019-18835CriNov 8, 2019
    risk 0.57cvss 9.8epss 0.01

    Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers.

  • CVE-2023-38686CriAug 4, 2023
    risk 0.53cvss 9.3epss 0.00

    Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send emails using TLS, Sydent does not verify SMTP servers' certificates. This makes Sydent's emails vulnerable to interception via a man-in-the-middle (MITM) attack.…

  • CVE-2023-28427HigMar 28, 2023
    risk 0.53cvss 8.2epss 0.01

    matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 24.0.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability…

  • CVE-2023-28103HigMar 28, 2023
    risk 0.53cvss 8.2epss 0.01

    matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. In certain configurations, data sent by remote servers containing special strings in key locations could cause modifications of the `Object.prototype`, disrupting matrix-react-sdk functionality, causing denial…

  • CVE-2025-24024CriJan 21, 2025
    risk 0.52cvss 9.1epss 0.01

    Mjolnir is a moderation tool for Matrix. Mjolnir v1.9.0 responds to management commands from any room the bot is member of. This can allow users who aren't operators of the bot to use the bot's functions, including server administration components if enabled. Version 1.9.1…

  • CVE-2022-29166HigMay 5, 2022
    risk 0.52cvss 8.0epss 0.01

    matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate a Matrix user into executing IRC commands by having them reply to a maliciously crafted message. The vulnerability has been patched in matrix-appservice-irc…

  • CVE-2024-47824HigOct 15, 2024
    risk 0.50cvss epss 0.01

    matrix-react-sdk is react-based software development kit for inserting a Matrix chat/VOIP client into a web page. Starting in version 3.18.0 and before 3.102.0, matrix-react-sdk allows a malicious homeserver to potentially steal message keys for a room when a user invites…

  • CVE-2024-47080HigOct 15, 2024
    risk 0.50cvss epss 0.01

    matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript. In matrix-js-sdk versions versions 9.11.0 through 34.7.0, the method `MatrixClient.sendSharedHistoryKeys` is vulnerable to interception by malicious homeservers. The method was introduced by MSC3061)…

  • CVE-2018-16515HigSep 18, 2018
    risk 0.50cvss 8.8epss 0.02

    Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.

  • CVE-2024-52805HigDec 3, 2024
    risk 0.49cvss 7.5epss 0.01

    Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks.…

  • CVE-2024-38429HigJul 30, 2024
    risk 0.49cvss 7.5epss 0.00

    Matrix Tafnit v8 -  CWE-552: Files or Directories Accessible to External Parties

  • CVE-2022-39252HigSep 29, 2022
    risk 0.49cvss 8.6epss 0.01

    matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library. Prior to version 0.6, when a user requests a room key from their devices, the software correctly remembers the request. When the user receives…

  • CVE-2022-39250HigSep 29, 2022
    risk 0.49cvss 8.6epss 0.01

    Matrix JavaScript SDK is the Matrix Client-Server software development kit (SDK) for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver could interfere with the verification flow between two users, injecting its own cross-signing user…

  • CVE-2022-39251HigSep 28, 2022
    risk 0.49cvss 8.6epss 0.01

    Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield.…

  • CVE-2022-39248HigSep 28, 2022
    risk 0.49cvss 8.6epss 0.01

    matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a…

  • CVE-2020-26890HigNov 24, 2020
    risk 0.49cvss 7.5epss 0.03

    Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing remote attackers to execute a denial of service attack against the federation and common Matrix clients. If such a malformed event…

  • CVE-2019-11842HigMay 9, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.

  • CVE-2018-12423HigJun 14, 2018
    risk 0.49cvss 7.5epss 0.02

    In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.

  • CVE-2022-36060HigMar 28, 2023
    risk 0.46cvss 8.2epss 0.01

    matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. Events sent with special strings in key places can temporarily disrupt or impede the matrix-react-sdk from functioning properly, such as by causing room or event tile crashes. The remainder of the application…

  • CVE-2022-36059HigMar 28, 2023
    risk 0.46cvss 8.2epss 0.01

    matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. In versions prior to 19.4.0 events sent with special strings in key places can temporarily disrupt or impede the matrix-js-sdk from functioning properly, potentially impacting the consumer's ability…

  • CVE-2024-42347HigAug 6, 2024
    risk 0.43cvss 7.7epss 0.00

    matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages…

  • CVE-2021-29431HigApr 15, 2021
    risk 0.43cvss 7.7epss 0.01

    Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validation or IP address blacklisting. It is not possible to exfiltrate data or control request headers, but it might be possible to use…

  • CVE-2025-66622HigDec 9, 2025
    risk 0.42cvss 7.5epss 0.00

    matrix-sdk-base is the base component to build a Matrix client library. Versions 0.14.1 and prior are unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is…

  • CVE-2024-37302HigDec 3, 2024
    risk 0.42cvss 7.5epss 0.01

    Synapse is an open-source Matrix homeserver. Synapse versions before 1.106 are vulnerable to a disk fill attack, where an unauthenticated adversary can induce Synapse to download and cache large amounts of remote media. The default rate limit strategy is insufficient to mitigate…

  • CVE-2022-39249HigSep 28, 2022
    risk 0.42cvss 7.5epss 0.01

    Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some…

  • CVE-2022-39246HigSep 28, 2022
    risk 0.42cvss 7.5epss 0.01

    matrix-android-sdk2 is the Matrix SDK for Android. Prior to version 1.5.1, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some platforms, but this may be…

  • CVE-2021-41281HigNov 23, 2021
    risk 0.42cvss 7.5epss 0.02

    Synapse is a package for Matrix homeservers written in Python 3/Twisted. Prior to version 1.47.1, Synapse instances with the media repository enabled can be tricked into downloading a file from a remote server into an arbitrary directory. No authentication is required for the…

  • CVE-2021-29430HigApr 15, 2021
    risk 0.42cvss 7.5epss 0.02

    Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. A malicious user could send an HTTP request with a very large body, leading to memory exhaustion and denial of service. Sydent also does not limit response…

  • CVE-2018-12291HigJun 13, 2018
    risk 0.42cvss 7.5epss 0.02

    The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rules were not applied correctly.

  • CVE-2018-10657HigMay 2, 2018
    risk 0.42cvss 7.5epss 0.02

    Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018.

  • CVE-2022-39200HigSep 12, 2022
    risk 0.40cvss 7.3epss 0.00

    Dendrite is a Matrix homeserver written in Go. In affected versions events retrieved from a remote homeserver using the `/get_missing_events` path did not have their signatures verified correctly. This could potentially allow a remote homeserver to provide invalid/modified…

  • CVE-2025-54315HigOct 2, 2025
    risk 0.39cvss 7.1epss 0.00

    The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness.

  • CVE-2025-49090HigOct 2, 2025
    risk 0.39cvss 7.1epss 0.00

    The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution.

  • CVE-2025-30355HigMar 27, 2025
    risk 0.39cvss 7.1epss 0.01

    Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with other servers. The vulnerability has been exploited in the wild and has been fixed in Synapse…

  • CVE-2021-40824MedSep 13, 2021
    risk 0.38cvss 5.9epss 0.01

    A logic error in the room key sharing functionality of Element Android before 1.2.2 and matrix-android-sdk2 (aka Matrix SDK for Android) before 1.2.2 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol…

  • CVE-2021-21332MedMar 26, 2021
    risk 0.38cvss 6.9epss 0.01

    Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the password reset endpoint served via Synapse was vulnerable to cross-site scripting…

  • CVE-2024-38432MedJul 30, 2024
    risk 0.36cvss 5.5epss 0.00

    Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File

  • CVE-2025-23197MedJan 27, 2025
    risk 0.35cvss 6.5epss 0.00

    matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. When Hookshot 6 version 6.0.1 or below, or Hookshot 5 version 5.4.1 or below, is configured with GitHub support, it is vulnerable to a Denial of Service (DoS) whereby it can…

  • CVE-2024-38430MedJul 30, 2024
    risk 0.35cvss 5.4epss 0.00

    Matrix - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CVE-2024-31208MedApr 23, 2024
    risk 0.35cvss 6.5epss 0.01

    Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in the V2 state resolution algorithm. This can induce high CPU consumption…

  • CVE-2022-39374MedMay 26, 2023
    risk 0.35cvss 6.5epss 0.01

    Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. If Synapse and a malicious homeserver are both joined to the same room, the malicious homeserver can trick Synapse into accepting previously rejected events into its view of the…

  • CVE-2022-41952MedNov 22, 2022
    risk 0.35cvss 6.5epss 0.01

    Synapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs without properly limiting connection time. Connections will only be terminated after `max_spider_size` (default: 10M) bytes have been downloaded, which can in…

  • CVE-2022-31152MedSep 2, 2022
    risk 0.35cvss 6.4epss 0.01

    Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. The Matrix specification specifies a list of [event authorization rules](https://spec.matrix.org/v1.2/rooms/v9/#authorization-rules) which must be checked when determining if an…

  • CVE-2022-31052MedJun 28, 2022
    risk 0.35cvss 6.5epss 0.02

    Synapse is an open source home server implementation for the Matrix chat network. In versions prior to 1.61.1 URL previews of some web pages can exhaust the available stack space for the Synapse process due to unbounded recursion. This is sometimes recoverable and leads to an…

  • CVE-2021-32659MedJun 16, 2021
    risk 0.35cvss 6.5epss 0.01

    Matrix-appservice-bridge is the bridging service for the Matrix communication program's application services. In versions 2.6.0 and earlier, if a bridge has room upgrade handling turned on in the configuration (the `roomUpgradeOpts` key when instantiating a new `Bridge`…

  • CVE-2020-26257MedDec 9, 2020
    risk 0.35cvss 6.5epss 0.02

    Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix. A malicious or poorly-implemented homeserver can inject malformed events into a room by specifying a different room id in the path of a…

Page 1 of 3