CVE-2025-49090 describes a high-severity vulnerability in the Matrix specification, specifically affecting versions before 1.16 (room versions prior to 12 and State Resolution before 2.1) due to deficient state resolution. This flaw carries a CVSS score of 7.1 (HIGH), indicating a network-based attack with high complexity, requiring low privileges, and capable of high integrity impact and low availability impact. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered community discussion and media coverage, suggesting awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Matrix | Matrix Specification | >= 0, < 1.16CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Coordinated Security Fix for Matrix Federation Protocol Vulnerabilities (Project Hydra)
Aug 14, 2025Project Hydra: Full Disclosure of State Resolution Security Improvements and Coordinated Release
Aug 14, 2025High Severity Federation Protocol Vulnerabilities (Project Hydra)
Aug 11, 2025Pre-disclosure: Upcoming coordinated security fix for all Matrix server implementations
Jul 16, 2025