vciy

CVEs we hold for Matrix-org

Records whose assigning authority named Matrix-org as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-63097Dendrite 0.13.8 syncapi /context Endpoint Post-Leave State Exposurematrix-org dendrite
CVE-2026-63096Dendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download Endpointmatrix-org dendrite
CVE-2026-63095Dendrite 0.13.8 Improper Authorization via POST account/3pid/delete Endpointmatrix-org dendrite
CVE-2026-45057matrix-sdk-ui: Incomplete edit validationmatrix-org matrix-sdk-ui
CVE-2026-45056Matrix Rust SDK: Sender-binding gaps in to-device and room-key attributionmatrix-org matrix-rust-sdk
CVE-2025-66622matrix-sdk-base is vulnerable to DoS via custom m.room.join_rules event valuesmatrix-org matrix-rust-sdk
CVE-2025-59160matrix-js-sdk has insufficient validation when considering a room to be upgraded by anothermatrix-org matrix-js-sdk
CVE-2025-59047matrix-sdk-base has panic in the `RoomMember::normalized_power_level()` methodmatrix-org matrix-rust-sdk
CVE-2025-53549Matrix Rust SDK allows SQL injection in the EventCache implementationmatrix-org matrix-rust-sdk
CVE-2025-48937matrix-sdk-crypto vulnerable to sender of encrypted events being spoofed by homeserver administratormatrix-org matrix-rust-sdk
CVE-2025-27155In-memory stored Cross-site scripting (XSS) vulnerability in pineconesimmatrix-org pinecone
CVE-2025-27146Matrix IRC Bridge allows IRC command injection to own puppeted usermatrix-org matrix-appservice-irc
CVE-2025-24024Mjolnir v1.9.0 accepts commands from any roommatrix-org mjolnir
CVE-2025-23197matrix-hookshot has a Potential Denial of Service when Hookshot is configured with GitHub supportmatrix-org matrix-hookshot
CVE-2024-52813matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identitymatrix-org matrix-rust-sdk
CVE-2024-52594Server-Side Request Forgery (SSRF) on redirects and federation in gomatrixserverlibmatrix-org gomatrixserverlib
CVE-2024-52505matrix-appservice-irc allows IRC Command injection in provisioning APImatrix-org matrix-appservice-irc
CVE-2024-50336matrix-js-sdk has insufficient MXC URI validation which allows client-side path traversalmatrix-org matrix-js-sdk
CVE-2024-47824Malicious homeservers can steal message keys when the matrix-react-sdk user invites another user to a roommatrix-org matrix-react-sdk
CVE-2024-47080matrix-js-sdk keys sent via `sendSharedHistoryKeys` vulnerable to interception by malicious homeservermatrix-org matrix-js-sdk
CVE-2024-42369A room with itself as a its predecessor will freeze matrix-js-sdkmatrix-org matrix-js-sdk
CVE-2024-42347URL preview setting for a room is controllable by the homeserver in matrix-react-sdkmatrix-org matrix-react-sdk
CVE-2024-40648`UserIdentity::is_verified` not checking verification status of own user identity while performing the check in…matrix-org matrix-rust-sdk
CVE-2024-40640Usage of non-constant time base64 decoder could lead to leakage of secret key material in vodozemacmatrix-org vodozemac
CVE-2024-39691Malicious Matrix homeserver can leak truncated message content of messages it shouldn't have access tomatrix-org matrix-appservice-irc
CVE-2024-34353matrix-sdk-crypto contains a log exposure of private key of the server-side key backupmatrix-org matrix-sdk-crypto
CVE-2024-34063Degraded secret zeroization capabilities in vodozemacmatrix-org vodozemac
CVE-2024-32000Truncated content of messages can be leaked from matrix-appservice-ircmatrix-org matrix-appservice-irc
CVE-2023-45129matrix-synapse vulnerable to denial of service due to malicious server ACL eventsmatrix-org synapse
CVE-2023-43796Synapse vulnerable to leak of remote user device informationmatrix-org synapse
CVE-2023-43656Sandbox escape for instances that have enabled transformation functions in matrix-hookshotmatrix-org matrix-hookshot
CVE-2023-42453Improper validation of receipts allows forged read receipts in matrix synapsematrix-org synapse
CVE-2023-41335Temporary storage of plaintext passwords during password changes in matrix synapsematrix-org synapse
CVE-2023-38700matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged roomsmatrix-org matrix-appservice-irc
CVE-2023-38691matrix-appservice-bridge doesn't verify the sub parameter of an openId token exhange, allowing unauthorized access to…matrix-org matrix-appservice-bridge
CVE-2023-38690matrix-appservice-irc IRC command injection via admin commands containing newlinesmatrix-org matrix-appservice-irc
CVE-2023-38686Sydent does not verify email server certificatesmatrix-org sydent
CVE-2023-37259Cross site scripting in Export Chat featurematrix-org matrix-react-sdk
CVE-2023-32683URL deny list bypass via oEmbed and image URLs when generating previews in Synapsematrix-org synapse
CVE-2023-32682Improper checks for deactivated users during login in synapsematrix-org synapse
CVE-2023-32323Synapse Outgoing federation to specific hosts can be disabled by sending malicious invitesmatrix-org synapse
CVE-2023-30609matrix-react-sdk vulnerable to HTML injection in search results via plaintext message highlightingmatrix-org matrix-react-sdk
CVE-2023-29529matrix-js-sdk vulnerable to invisible eavesdropping in group callsmatrix-org matrix-js-sdk
CVE-2023-28427Prototype pollution in matrix-js-sdkmatrix-org matrix-js-sdk
CVE-2023-28103Prototype pollution in matrix-react-sdkmatrix-org matrix-react-sdk
CVE-2022-41952Uncontrolled Resource Consumption in Matrix Synapsematrix-org synapse
CVE-2022-39374Synapse Denial of service due to incorrect application of event authorization rules during state resolutionmatrix-org synapse
CVE-2022-39335Synapse does not apply enough checks to servers requesting auth events of events in a roommatrix-org synapse
CVE-2022-39257Matrix iOS SDK vulnerable to impersonation via forwarded Megolm sessionsmatrix-org matrix-ios-sdk
CVE-2022-39255Matrix iOS SDK vulnerable ton Olm/Megolm protocol confusionmatrix-org matrix-ios-sdk
CVE-2022-39252When matrix-rust-sdk recieves forwarded room keys, the reciever doesn't check if it requested the key from the forwardermatrix-org matrix-rust-sdk
CVE-2022-39251Matrix Javascript SDK vulnerable to Olm/Megolm protocol confusionmatrix-org matrix-js-sdk
CVE-2022-39250Matrix JavaScript SDK vulnerable to key/device identifier confusion in SAS verificationmatrix-org matrix-js-sdk
CVE-2022-39249Matrix Javascript SDK vulnerable to impersonation via forwarded Megolm sessionsmatrix-org matrix-js-sdk
CVE-2022-39248matrix-android-sdk2 vulnerable to Olm/Megolm protocol confusionmatrix-org matrix-android-sdk2
CVE-2022-39246matrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessionsmatrix-org matrix-android-sdk2
CVE-2022-39236Matrix Javascript SDK improper beacon events can cause availability issuesmatrix-org matrix-js-sdk
CVE-2022-39203Parsing issue in matrix-org/node-irc leading to room takeoversmatrix-org matrix-appservice-irc
CVE-2022-39202IRC mode parameter confusion in matrix-appservice-ircmatrix-org matrix-appservice-irc
CVE-2022-39200Signature checks not applied to some retrieved missing eventsmatrix-org dendrite
CVE-2022-36060Prototype pollution in matrix-react-sdkmatrix-org matrix-react-sdk
CVE-2022-36059Prototype pollution in matrix-js-sdkmatrix-org matrix-js-sdk
CVE-2022-36009Incorrect parsing of access level in gomatrixserverlib and dendritematrix-org gomatrixserverlib
CVE-2022-31152Synapse vulnerable to denial of service (DoS) due to incorrect application of event authorization rulesmatrix-org synapse
CVE-2022-31052URL previews can crash Synapse media repositories or Synapse monolithsmatrix-org synapse
CVE-2022-29166Improper handling of multiline messages in matrix-appservice-ircmatrix-org matrix-appservice-irc
CVE-2021-41281Path traversal in Matrix Synapsematrix-org synapse
CVE-2021-39164Improper authorisation of /members discloses room membership to non-membersmatrix-org synapse
CVE-2021-39163Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.matrix-org synapse
CVE-2021-32659Automatic room upgrade handling can be used maliciously to bridge a room non-consentuallymatrix-org matrix-appservice-bridge
CVE-2021-32622File upload local preview can run embedded scripts after user interactionmatrix-org matrix-react-sdk
CVE-2021-29471Denial of service in Matrix Synapsematrix-org synapse
CVE-2021-29433Denial of service (via resource exhaustion) due to improper input validationmatrix-org sydent
CVE-2021-29432Malicious users could control the content of invitation emailsmatrix-org sydent
CVE-2021-29431SSRF in Sydent due to missing validation of hostnamesmatrix-org sydent
CVE-2021-29430Denial of service attack via memory exhaustionmatrix-org sydent
CVE-2021-21394Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpointsmatrix-org synapse
CVE-2021-21393Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpointsmatrix-org synapse
CVE-2021-21392Open redirect via transitional IPv6 addresses on dual-stack networksmatrix-org synapse
CVE-2021-21333HTML injection in email and account expiry notificationsmatrix-org synapse
CVE-2021-21332Cross-site scripting (XSS) vulnerability in the password reset endpointmatrix-org synapse
CVE-2021-21320User content sandbox can be confused into opening arbitrary documentsmatrix-org matrix-react-sdk
CVE-2021-21274Denial of service attack via .well-known lookupsmatrix-org synapse
CVE-2021-21273Open redirects on some federation and push requestsmatrix-org synapse
CVE-2020-26257Denial of service attack via incorrect parameters to federation APIsmatrix-org synapse

85 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.