Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-36059

19
FAUCET Score

CVE-2022-36059 is a medium-severity vulnerability affecting the matrix-js-sdk, a JavaScript client-server SDK for the Matrix messaging protocol, in versions prior to 19.4.0. This flaw allows specially crafted events to temporarily disrupt or impede the SDK's functionality, potentially leading to data exclusion or corruption without immediately apparent errors. The vulnerability has a CVSS score of 5.3, indicating a network-based attack with low complexity and no user interaction required, primarily impacting data integrity (CWE-1321). There is currently no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 19.4.0CPE matchmatch criteria
cpe:2.3:a:matrix:javascript_sdk:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

8.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.94%
Probability of exploitation in next 30 days
EPSS Percentile
57.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0094 is in the 36th percentile among its peer group of 23,701 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

harborpatch availablevia llm_extracted
Fixed in: matrix-js-sdk 19.4.0, matrix-react-sdk 3.53.0
View patch
netgearpatch availablevia llm_extracted
Fixed in: matrix-js-sdk 19.4.0
View patch
npmpatch availablevia ghsa
Product: matrix-js-sdkFixed in: 19.4.0
phoenix_contactpatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsFixed in: thunderbird-0:102.3.0-3.el8_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Extended Update SupportFixed in: thunderbird-0:102.3.0-3.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update SupportFixed in: thunderbird-0:102.3.0-3.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: thunderbird-0:102.3.0-3.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: thunderbird-0:102.3.0-3.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: thunderbird-0:102.3.0-3.el7_9
View patch
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (5)

harborllm-harbor-20ffd6fa7c2461e3HIGH

Previously Disclosed Prototype Pollution Vulnerabilities in matrix-js-sdk and matrix-react-sdk

Mar 29, 2023
netgearllm-netgear-bdb99a610971de06HIGH

Prototype Pollution in matrix-js-sdk (previously announced)

Mar 29, 2023
phoenix_contactllm-phoenix_contact-9abfaf72a2822a0bHIGH

High-severity Prototype Pollution vulnerabilities in matrix-js-sdk and matrix-react-sdk

Mar 29, 2023
npmGHSA-rfv9-x7hh-xc32high

matrix-js-sdk Prototype Pollution vulnerability

Mar 28, 2023
redhatCVE-2022-36059Moderate

Mozilla: Matrix SDK bundled with Thunderbird vulnerable to denial-of-service attack

Aug 31, 2022

References

github.com / matrix-org/matrix-js-sdk/security/advisories/GHSA-rfv9-x7hh-xc32
Vendor Advisory