VYPR

Vendor CVEs

Matrix Org

All CVEs

115 total · sorted by risk
  • CVE-2024-34063LowMay 3, 2024
    risk 0.09cvss 2.5epss 0.00

    vodozemac is an implementation of Olm and Megolm in pure Rust. Versions 0.5.0 and 0.5.1 of vodozemac have degraded secret zeroization capabilities, due to changes in third-party cryptographic dependencies (the Dalek crates), which moved secret zeroization capabilities behind a…

  • CVE-2026-45057Jun 4, 2026
    risk 0.00cvss epss 0.00

    ### Impact The message edit validation logic in the `matrix-sdk-ui` crate before 0.16.1 is missing a check: when replacing an encrypted event, the replacement event itself is not required to be encrypted. This enables a malicious homeserver administrator (or an actor with…

  • CVE-2026-45056Jun 4, 2026
    risk 0.00cvss epss 0.00

    ### Impact The `matrix-sdk-crypto` crate before 0.16.1 is missing a check for the sender's user ID when decrypting an Olm-encrypted to-device message containing the `sender_device_keys` property. This could be exploited to spoof the sender of an encrypted to-device message,…

  • CVE-2024-45193MedAug 22, 2024
    risk 0.00cvss 4.3epss 0.00

    An issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due to lack of validation criteria (does not ensure that S < n). This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that are no longer…

  • CVE-2024-45192MedAug 22, 2024
    risk 0.00cvss 5.3epss 0.01

    An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decoding group session keys. This refers to the libolm implementation of Olm. NOTE: This vulnerability only affects products that are no longer supported by the…

  • CVE-2024-45191MedAug 22, 2024
    risk 0.00cvss 5.3epss 0.00

    An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cache-timing attacks due to use of S-boxes. This is related to software that uses a lookup table for the SubWord step. This refers to the libolm implementation of Olm. NOTE: This…

  • CVE-2023-43656MedSep 27, 2023
    risk 0.00cvss 5.6epss 0.00

    matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. Instances that have enabled transformation functions (those that have `generic.allowJsTransformationFunctions` in their config), may be vulnerable to an attack where it is…

  • CVE-2022-39257HigSep 28, 2022
    risk 0.00cvss 7.5epss 0.01

    Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker cooperating with a malicious homeserver can construct messages appearing to have come from another person. Such messages will be marked with a grey shield on some…

  • CVE-2022-39255HigSep 28, 2022
    risk 0.00cvss 8.6epss 0.01

    Matrix iOS SDK allows developers to build iOS apps compatible with Matrix. Prior to version 0.23.19, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey…

  • CVE-2021-34813CriJun 16, 2021
    risk 0.00cvss 9.8epss 0.04

    Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because olm_pk_decrypt has a stack-based buffer overflow. Remote code execution might be possible for some…

  • CVE-2021-32622MedMay 17, 2021
    risk 0.00cvss 4.2epss 0.00

    Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, when uploading a file, the local file preview can lead to execution of scripts embedded in the uploaded file. This can only occur after several user interactions…

  • CVE-2021-21394MedApr 12, 2021
    risk 0.00cvss 5.3epss 0.02

    Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input validation of some parameters on the endpoints used to…

  • CVE-2020-26891MedOct 19, 2020
    risk 0.00cvss 6.1epss 0.02

    AuthRestServlet in Matrix Synapse before 1.21.0 is vulnerable to XSS due to unsafe interpolation of the session GET parameter. This allows a remote attacker to execute an XSS attack on the domain Synapse is hosted on, by supplying the victim user with a malicious URL to the…

  • CVE-2019-5885HigMar 21, 2019
    risk 0.00cvss 7.5epss 0.02

    Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.

  • CVE-2004-2089Feb 6, 2004
    risk 0.00cvss epss 0.02

    Matrix FTP Server allows remote attackers to cause a denial of service (crash) by logging in using four spaces as the username and password and then issuing a LIST command.

Page 3 of 3