CVE-2026-45056Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution Exploitation status Not confirmed Fix YesAffected product M matrix-rust-sdk Published 09/11/2026 Severity Medium CVE-2026-45057matrix-sdk-ui: Incomplete edit validation Exploitation status Not confirmed Fix Not confirmed Affected product M matrix-sdk-ui Published 09/11/2026 Severity Medium CVE-2026-63097Dendrite 0.13.8 syncapi /context Endpoint Post-Leave State Exposure Exploitation status Public exploit Fix Not confirmed Affected product D dendrite Published 07/17/2026 Severity Medium CVE-2026-63096Dendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download Endpoint Exploitation status Public exploit Fix Not confirmed Affected product D dendrite Published 07/17/2026 Severity Medium CVE-2026-63095Dendrite 0.13.8 Improper Authorization via POST account/3pid/delete Endpoint Exploitation status Public exploit Fix Not confirmed Affected product D dendrite Published 07/17/2026 Severity High CVE-2025-66622matrix-sdk-base is vulnerable to DoS via custom m.room.join_rules event values Exploitation status Not known exploited Fix YesAffected product M matrix-rust-sdk Published 12/09/2025 Severity Low CVE-2025-59160matrix-js-sdk has insufficient validation when considering a room to be upgraded by another Exploitation status Not known exploited Fix Not confirmed Affected product M matrix-js-sdk Published 09/16/2025 Severity Low CVE-2025-59047matrix-sdk-base has panic in the `RoomMember::normalized_power_level()` method Exploitation status Not known exploited Fix YesAffected product M matrix-rust-sdk Published 09/11/2025 Severity Low CVE-2025-53549Matrix Rust SDK allows SQL injection in the EventCache implementation Exploitation status Not known exploited Fix YesAffected product M matrix-rust-sdk Published 07/10/2025 Severity Medium CVE-2025-48937matrix-sdk-crypto vulnerable to sender of encrypted events being spoofed by homeserver administrator Exploitation status Not known exploited Fix YesAffected product M matrix-rust-sdk Published 06/10/2025 Severity Medium CVE-2025-27155In-memory stored Cross-site scripting (XSS) vulnerability in pineconesim Exploitation status Not known exploited Fix Not confirmed Affected product P pinecone Published 03/04/2025 Severity Medium CVE-2025-27146Matrix IRC Bridge allows IRC command injection to own puppeted user Exploitation status Not known exploited Fix YesAffected product M matrix-appservice-irc Published 02/25/2025 Severity Low CVE-2025-23197matrix-hookshot has a Potential Denial of Service when Hookshot is configured with GitHub support Exploitation status Not known exploited Fix YesAffected product M matrix-hookshot Published 01/27/2025 Severity Medium CVE-2025-24024Mjolnir v1.9.0 accepts commands from any room Exploitation status Not known exploited Fix Not confirmed Affected product M mjolnir Published 01/21/2025 Severity Critical CVE-2024-52594Server-Side Request Forgery (SSRF) on redirects and federation in gomatrixserverlib Exploitation status Not known exploited Fix Not confirmed Affected product G gomatrixserverlib Published 01/16/2025 Severity Medium CVE-2024-52813matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity Exploitation status Not known exploited Fix Not confirmed Affected product M matrix-rust-sdk Published 01/07/2025 Severity Medium CVE-2024-52505matrix-appservice-irc allows IRC Command injection in provisioning API Exploitation status Not known exploited Fix YesAffected product M matrix-appservice-irc Published 11/14/2024 Severity Medium CVE-2024-50336matrix-js-sdk has insufficient MXC URI validation which allows client-side path traversal Exploitation status Not known exploited Fix YesAffected product M matrix-js-sdk Published 11/12/2024 Severity Medium CVE-2024-47824Malicious homeservers can steal message keys when the matrix-react-sdk user invites another user to a room Exploitation status Not known exploited Fix Not confirmed Affected product M matrix-react-sdk Published 10/15/2024 Severity High CVE-2024-47080matrix-js-sdk keys sent via `sendSharedHistoryKeys` vulnerable to interception by malicious homeserver Exploitation status Not known exploited Fix YesAffected product M matrix-js-sdk Published 10/15/2024 Severity High CVE-2024-42369A room with itself as a its predecessor will freeze matrix-js-sdk Exploitation status Not known exploited Fix YesAffected product M matrix-js-sdk Published 08/20/2024 Severity Medium CVE-2024-42347URL preview setting for a room is controllable by the homeserver in matrix-react-sdk Exploitation status Not known exploited Fix YesAffected product M matrix-react-sdk Published 08/06/2024 Severity High CVE-2024-40648`UserIdentity::is_verified` not checking verification status of own user identity while performing the check in matrix-rust-sdk Exploitation status Not known exploited Fix Not confirmed Affected product M matrix-rust-sdk Published 07/18/2024 Severity Medium CVE-2024-40640Usage of non-constant time base64 decoder could lead to leakage of secret key material in vodozemac Exploitation status Not known exploited Fix YesAffected product V vodozemac Published 07/17/2024 Severity Low CVE-2024-39691Malicious Matrix homeserver can leak truncated message content of messages it shouldn't have access to Exploitation status Not known exploited Fix Not confirmed Affected product M matrix-appservice-irc Published 07/05/2024 Severity Medium CVE-2024-34353matrix-sdk-crypto contains a log exposure of private key of the server-side key backup Exploitation status Not known exploited Fix YesAffected product M matrix-sdk-crypto Published 05/13/2024 Severity Medium CVE-2024-34063Degraded secret zeroization capabilities in vodozemac Exploitation status Not known exploited Fix Not confirmed Affected product V vodozemac Published 05/03/2024 Severity Low CVE-2024-32000Truncated content of messages can be leaked from matrix-appservice-irc Exploitation status Not known exploited Fix Not confirmed Affected product M matrix-appservice-irc Published 04/12/2024 Severity Medium CVE-2023-43796Synapse vulnerable to leak of remote user device information Exploitation status Not confirmed Fix Not confirmed Affected product S synapse Published 10/31/2023 Severity Medium CVE-2023-45129matrix-synapse vulnerable to denial of service due to malicious server ACL events Exploitation status Not confirmed Fix Not confirmed Affected product S synapse Published 10/10/2023 Severity Medium CVE-2023-43656Sandbox escape for instances that have enabled transformation functions in matrix-hookshot Exploitation status Not known exploited Fix Not confirmed Affected product M matrix-hookshot Published 09/27/2023 Severity Medium CVE-2023-41335Temporary storage of plaintext passwords during password changes in matrix synapse Exploitation status Not confirmed Fix Not confirmed Affected product S synapse Published 09/26/2023 Severity Low CVE-2023-42453Improper validation of receipts allows forged read receipts in matrix synapse Exploitation status Not known exploited Fix YesAffected product S synapse Published 09/26/2023 Severity Low CVE-2023-38700matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged rooms Exploitation status Not known exploited Fix Not confirmed Affected product M matrix-appservice-irc Published 08/04/2023 Severity Low CVE-2023-38691matrix-appservice-bridge doesn't verify the sub parameter of an openId token exhange, allowing unauthorized access to provisioning APIs Exploitation status Not known exploited Fix Not confirmed Affected product M matrix-appservice-bridge Published 08/04/2023 Severity Medium CVE-2023-38690matrix-appservice-irc IRC command injection via admin commands containing newlines Exploitation status Not known exploited Fix Not confirmed Affected product M matrix-appservice-irc Published 08/04/2023 Severity Medium CVE-2023-38686Sydent does not verify email server certificates Exploitation status Public exploit Fix YesAffected product S sydent Published 08/04/2023 Severity Critical CVE-2023-37259Cross site scripting in Export Chat feature Exploitation status Not known exploited Fix Not confirmed Affected product M matrix-react-sdk Published 07/18/2023 Severity Medium CVE-2023-32683URL deny list bypass via oEmbed and image URLs when generating previews in Synapse Exploitation status Not known exploited Fix Not confirmed Affected product S synapse Published 06/06/2023 Severity Low CVE-2023-32682Improper checks for deactivated users during login in synapse Exploitation status Not known exploited Fix Not confirmed Affected product S synapse Published 06/06/2023 Severity Medium CVE-2022-39374Synapse Denial of service due to incorrect application of event authorization rules during state resolution Exploitation status Not known exploited Fix YesAffected product S synapse Published 05/26/2023 Severity Medium CVE-2022-39335Synapse does not apply enough checks to servers requesting auth events of events in a room Exploitation status Not known exploited Fix YesAffected product S synapse Published 05/26/2023 Severity Medium CVE-2023-32323Synapse Outgoing federation to specific hosts can be disabled by sending malicious invites Exploitation status Public exploit Fix Not confirmed Affected product S synapse Published 05/26/2023 Severity Medium CVE-2023-30609matrix-react-sdk vulnerable to HTML injection in search results via plaintext message highlighting Exploitation status Not known exploited Fix Not confirmed Affected product M matrix-react-sdk Published 04/25/2023 Severity Medium CVE-2023-29529matrix-js-sdk vulnerable to invisible eavesdropping in group calls Exploitation status Not known exploited Fix YesAffected product M matrix-js-sdk Published 04/14/2023 Severity Medium CVE-2022-36060Prototype pollution in matrix-react-sdk Exploitation status Not known exploited Fix YesAffected product M matrix-react-sdk Published 03/28/2023 Severity High CVE-2023-28103Prototype pollution in matrix-react-sdk Exploitation status Not known exploited Fix YesAffected product M matrix-react-sdk Published 03/28/2023 Severity High CVE-2023-28427Prototype pollution in matrix-js-sdk Exploitation status Not known exploited Fix YesAffected product M matrix-js-sdk Published 03/28/2023 Severity High CVE-2022-36059Prototype pollution in matrix-js-sdk Exploitation status Not known exploited Fix YesAffected product M matrix-js-sdk Published 03/28/2023 Severity High CVE-2022-41952Uncontrolled Resource Consumption in Matrix Synapse Exploitation status Not known exploited Fix Not confirmed Affected product S synapse Published 11/22/2022 Severity Medium CVE-2022-39252When matrix-rust-sdk recieves forwarded room keys, the reciever doesn't check if it requested the key from the forwarder Exploitation status Not known exploited Fix Not confirmed Affected product M matrix-rust-sdk Published 09/29/2022 Severity High CVE-2022-39250Matrix JavaScript SDK vulnerable to key/device identifier confusion in SAS verification Exploitation status Not known exploited Fix Not confirmed Affected product M matrix-js-sdk Published 09/29/2022 Severity High CVE-2022-39257Matrix iOS SDK vulnerable to impersonation via forwarded Megolm sessions Exploitation status Not known exploited Fix Not confirmed Affected product M matrix-ios-sdk Published 09/28/2022 Severity High CVE-2022-39255Matrix iOS SDK vulnerable ton Olm/Megolm protocol confusion Exploitation status Not known exploited Fix Not confirmed Affected product M matrix-ios-sdk Published 09/28/2022 Severity High CVE-2022-39248matrix-android-sdk2 vulnerable to Olm/Megolm protocol confusion Exploitation status Not known exploited Fix Not confirmed Affected product M matrix-android-sdk2 Published 09/28/2022 Severity High CVE-2022-39246matrix-android-sdk2 vulnerable to impersonation via forwarded Megolm sessions Exploitation status Not known exploited Fix Not confirmed Affected product M matrix-android-sdk2 Published 09/28/2022 Severity High CVE-2022-39236Matrix Javascript SDK improper beacon events can cause availability issues Exploitation status Not known exploited Fix YesAffected product M matrix-js-sdk Published 09/28/2022 Severity Medium CVE-2022-39249Matrix Javascript SDK vulnerable to impersonation via forwarded Megolm sessions Exploitation status Not known exploited Fix Not confirmed Affected product M matrix-js-sdk Published 09/28/2022 Severity High CVE-2022-39251Matrix Javascript SDK vulnerable to Olm/Megolm protocol confusion Exploitation status Not known exploited Fix Not confirmed Affected product M matrix-js-sdk Published 09/28/2022 Severity High CVE-2022-39203Parsing issue in matrix-org/node-irc leading to room takeovers Exploitation status Not known exploited Fix YesAffected product M matrix-appservice-irc Published 09/13/2022 Severity High CVE-2022-39202IRC mode parameter confusion in matrix-appservice-irc Exploitation status Not known exploited Fix YesAffected product M matrix-appservice-irc Published 09/13/2022 Severity Medium CVE-2022-39200Signature checks not applied to some retrieved missing events Exploitation status Not known exploited Fix YesAffected product D dendrite Published 09/12/2022 Severity High CVE-2022-31152Synapse vulnerable to denial of service (DoS) due to incorrect application of event authorization rules Exploitation status Not known exploited Fix Not confirmed Affected product S synapse Published 09/02/2022 Severity Medium CVE-2022-36009Incorrect parsing of access level in gomatrixserverlib and dendrite Exploitation status Not known exploited Fix Not confirmed Affected product G gomatrixserverlib Published 08/19/2022 Severity Medium CVE-2022-31052URL previews can crash Synapse media repositories or Synapse monoliths Exploitation status Not known exploited Fix Not confirmed Affected product S synapse Published 06/28/2022 Severity Medium CVE-2022-29166Improper handling of multiline messages in matrix-appservice-irc Exploitation status Not known exploited Fix YesAffected product M matrix-appservice-irc Published 05/05/2022 Severity High CVE-2021-41281Path traversal in Matrix Synapse Exploitation status Not confirmed Fix Not confirmed Affected product S synapse Published 11/23/2021 Severity High CVE-2021-39164Improper authorisation of /members discloses room membership to non-members Exploitation status Not confirmed Fix Not confirmed Affected product S synapse Published 08/31/2021 Severity Low CVE-2021-39163Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner. Exploitation status Not confirmed Fix Not confirmed Affected product S synapse Published 08/31/2021 Severity Low CVE-2021-32659Automatic room upgrade handling can be used maliciously to bridge a room non-consentually Exploitation status Not confirmed Fix Not confirmed Affected product M matrix-appservice-bridge Published 06/16/2021 Severity Medium CVE-2021-32622File upload local preview can run embedded scripts after user interaction Exploitation status Not confirmed Fix YesAffected product M matrix-react-sdk Published 05/17/2021 Severity Medium CVE-2021-29471Denial of service in Matrix Synapse Exploitation status Not confirmed Fix YesAffected product S synapse Published 05/11/2021 Severity Low CVE-2021-29431SSRF in Sydent due to missing validation of hostnames Exploitation status Not confirmed Fix Not confirmed Affected product S sydent Published 04/15/2021 Severity High CVE-2021-29432Malicious users could control the content of invitation emails Exploitation status Not confirmed Fix YesAffected product S sydent Published 04/15/2021 Severity Medium CVE-2021-29430Denial of service attack via memory exhaustion Exploitation status Not confirmed Fix YesAffected product S sydent Published 04/15/2021 Severity High CVE-2021-29433Denial of service (via resource exhaustion) due to improper input validation Exploitation status Not confirmed Fix Not confirmed Affected product S sydent Published 04/15/2021 Severity Medium CVE-2021-21392Open redirect via transitional IPv6 addresses on dual-stack networks Exploitation status Not confirmed Fix Not confirmed Affected product S synapse Published 04/12/2021 Severity Medium CVE-2021-21393Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints Exploitation status Not confirmed Fix Not confirmed Affected product S synapse Published 04/12/2021 Severity Medium CVE-2021-21394Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints Exploitation status Not confirmed Fix Not confirmed Affected product S synapse Published 04/12/2021 Severity Medium CVE-2021-21333HTML injection in email and account expiry notifications Exploitation status Not confirmed Fix YesAffected product S synapse Published 03/26/2021 Severity Medium CVE-2021-21332Cross-site scripting (XSS) vulnerability in the password reset endpoint Exploitation status Not confirmed Fix YesAffected product S synapse Published 03/26/2021 Severity Medium CVE-2021-21320User content sandbox can be confused into opening arbitrary documents Exploitation status Not confirmed Fix YesAffected product M matrix-react-sdk Published 03/02/2021 Severity Low CVE-2021-21273Open redirects on some federation and push requests Exploitation status Not confirmed Fix Not confirmed Affected product S synapse Published 02/26/2021 Severity Low CVE-2021-21274Denial of service attack via .well-known lookups Exploitation status Not confirmed Fix YesAffected product S synapse Published 02/26/2021 Severity Medium CVE-2020-26257Denial of service attack via incorrect parameters to federation APIs Exploitation status Not confirmed Fix YesAffected product S synapse Published 12/09/2020 Severity Medium