CVE Tools

Matrix

42 CVEs tracked since 2018. Since Jun 2018, none of them reached CISA KEV.

Matrix CVEs per month

Jun 2018 to Dec 2024. Point at a month, or focus the strip and use the arrow keys.
Matrix CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2018-0620
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-0220
2021-03null or fewer
2021-0470
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09130
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-0840
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-0740
2024-0850
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-1250

Products

The products that kept showing up in Matrix's monthly top three, with their CVEs summed over those months.

  1. Synapse124 months
  2. JavaScript Sdk52 months
  3. Sydent52 months
  4. Matrix Irc Bridge42 months
  5. Software Development Kit41 month
  6. Tafnit V841 month
  7. Olm31 month
  8. Matrix-appservice-bridge11 month
  9. Matrix-react-sdk11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Matrix.

  1. CVE-2025-54315The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness.7.1
  2. CVE-2025-49090The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution.7.1
  3. CVE-2025-30355Synapse vulnerable to federation denial of service via malformed events7.1
  4. CVE-2025-27146Matrix IRC Bridge allows IRC command injection to own puppeted user2.7
  5. CVE-2024-37303Synapse unauthenticated writes to the media repository allow planting of problematic content5.3
  6. CVE-2024-37302Synapse denial of service through media disk space consumption7.5
  7. CVE-2024-52805Synapse allows unsupported content types to lead to memory exhaustion7.5
  8. CVE-2024-52815Synapse allows a a malformed invite to break the invitee's `/sync`5.3
  9. CVE-2024-53863Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders9.1
  10. CVE-2024-45192An issue was discovered in Matrix libolm through 3.2.16. Cache-timing attacks can occur due to use of base64 when decoding group session keys. This refers to the libolm implementation of Olm. NOTE:...5.3
  11. CVE-2024-45191An issue was discovered in Matrix libolm through 3.2.16. The AES implementation is vulnerable to cache-timing attacks due to use of S-boxes. This is related to software that uses a lookup table for...5.3
  12. CVE-2024-45193An issue was discovered in Matrix libolm through 3.2.16. There is Ed25519 signature malleability due to lack of validation criteria (does not ensure that S < n). This refers to the libolm implement...4.3
  13. CVE-2024-42369A room with itself as a its predecessor will freeze matrix-js-sdk4.1
  14. CVE-2024-42347URL preview setting for a room is controllable by the homeserver in matrix-react-sdk7.7
  15. CVE-2024-38432Matrix – Tafnit v8 CWE-646: Reliance on File Name or Extension of Externally-Supplied File5.5

The record

Peak rank
#53 in Sep 2022
Busiest month shown
Sep 2022, 13 CVEs
Months with a KEV entry
0 since Jun 2018
Monthly snapshots
8 since 2018
Matrix's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store