Matrix-org
26 CVEs tracked since 2021. Since Feb 2021, none of them reached CISA KEV.
Matrix-org CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-02 | 2 | 0 |
| 2021-03 | null or fewer | |
| 2021-04 | 7 | 0 |
| 2021-05 | null or fewer | |
| 2021-06 | null or fewer | |
| 2021-07 | null or fewer | |
| 2021-08 | null or fewer | |
| 2021-09 | null or fewer | |
| 2021-10 | null or fewer | |
| 2021-11 | null or fewer | |
| 2021-12 | null or fewer | |
| 2022-01 | null or fewer | |
| 2022-02 | null or fewer | |
| 2022-03 | null or fewer | |
| 2022-04 | null or fewer | |
| 2022-05 | null or fewer | |
| 2022-06 | null or fewer | |
| 2022-07 | null or fewer | |
| 2022-08 | null or fewer | |
| 2022-09 | 13 | 0 |
| 2022-10 | null or fewer | |
| 2022-11 | null or fewer | |
| 2022-12 | null or fewer | |
| 2023-01 | null or fewer | |
| 2023-02 | null or fewer | |
| 2023-03 | null or fewer | |
| 2023-04 | null or fewer | |
| 2023-05 | null or fewer | |
| 2023-06 | null or fewer | |
| 2023-07 | null or fewer | |
| 2023-08 | 4 | 0 |
Products
The products that kept showing up in Matrix-org's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Matrix-org.
- CVE-2026-45056Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution—
- CVE-2026-45057matrix-sdk-ui: Incomplete edit validation4.9
- CVE-2026-63097Dendrite 0.13.8 syncapi /context Endpoint Post-Leave State Exposure4.3
- CVE-2026-63096Dendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download Endpoint5.8
- CVE-2026-63095Dendrite 0.13.8 Improper Authorization via POST account/3pid/delete Endpoint6.5
- CVE-2025-66622matrix-sdk-base is vulnerable to DoS via custom m.room.join_rules event values—
- CVE-2025-59160matrix-js-sdk has insufficient validation when considering a room to be upgraded by another—
- CVE-2025-59047matrix-sdk-base has panic in the `RoomMember::normalized_power_level()` method—
- CVE-2025-53549Matrix Rust SDK allows SQL injection in the EventCache implementation—
- CVE-2025-48937matrix-sdk-crypto vulnerable to sender of encrypted events being spoofed by homeserver administrator4.9
- CVE-2025-27155In-memory stored Cross-site scripting (XSS) vulnerability in pineconesim6.1
- CVE-2025-27146Matrix IRC Bridge allows IRC command injection to own puppeted user2.7
- CVE-2025-23197matrix-hookshot has a Potential Denial of Service when Hookshot is configured with GitHub support6.5
- CVE-2025-24024Mjolnir v1.9.0 accepts commands from any room9.1
- CVE-2024-52594Server-Side Request Forgery (SSRF) on redirects and federation in gomatrixserverlib4.3
The record
- Peak rank
- #54 in Sep 2022
- Busiest month shown
- Sep 2022, 13 CVEs
- Months with a KEV entry
- 0 since Feb 2021
- Monthly snapshots
- 4 since 2021