CVE Tools

Matrix-org

26 CVEs tracked since 2021. Since Feb 2021, none of them reached CISA KEV.

Matrix-org CVEs per month

Feb 2021 to Aug 2023. Point at a month, or focus the strip and use the arrow keys.
Matrix-org CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-0220
2021-03null or fewer
2021-0470
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09130
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-0840

Products

The products that kept showing up in Matrix-org's monthly top three, with their CVEs summed over those months.

  1. Sydent52 months
  2. Synapse52 months
  3. Matrix-appservice-irc42 months
  4. Matrix-js-sdk41 month
  5. Matrix-ios-sdk21 month
  6. Matrix-appservice-bridge11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Matrix-org.

  1. CVE-2026-45056Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution—
  2. CVE-2026-45057matrix-sdk-ui: Incomplete edit validation4.9
  3. CVE-2026-63097Dendrite 0.13.8 syncapi /context Endpoint Post-Leave State Exposure4.3
  4. CVE-2026-63096Dendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download Endpoint5.8
  5. CVE-2026-63095Dendrite 0.13.8 Improper Authorization via POST account/3pid/delete Endpoint6.5
  6. CVE-2025-66622matrix-sdk-base is vulnerable to DoS via custom m.room.join_rules event values—
  7. CVE-2025-59160matrix-js-sdk has insufficient validation when considering a room to be upgraded by another—
  8. CVE-2025-59047matrix-sdk-base has panic in the `RoomMember::normalized_power_level()` method—
  9. CVE-2025-53549Matrix Rust SDK allows SQL injection in the EventCache implementation—
  10. CVE-2025-48937matrix-sdk-crypto vulnerable to sender of encrypted events being spoofed by homeserver administrator4.9
  11. CVE-2025-27155In-memory stored Cross-site scripting (XSS) vulnerability in pineconesim6.1
  12. CVE-2025-27146Matrix IRC Bridge allows IRC command injection to own puppeted user2.7
  13. CVE-2025-23197matrix-hookshot has a Potential Denial of Service when Hookshot is configured with GitHub support6.5
  14. CVE-2025-24024Mjolnir v1.9.0 accepts commands from any room9.1
  15. CVE-2024-52594Server-Side Request Forgery (SSRF) on redirects and federation in gomatrixserverlib4.3

The record

Peak rank
#54 in Sep 2022
Busiest month shown
Sep 2022, 13 CVEs
Months with a KEV entry
0 since Feb 2021
Monthly snapshots
4 since 2021
Matrix-org's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store