Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-49090

24
FAUCET Score

CVE-2025-49090 describes a high-severity vulnerability in the Matrix specification, specifically affecting versions before 1.16 (room versions prior to 12 and State Resolution before 2.1) due to deficient state resolution. This flaw carries a CVSS score of 7.1 (HIGH), indicating a network-based attack with high complexity, requiring low privileges, and capable of high integrity impact and low availability impact. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered community discussion and media coverage, suggesting awareness within the cybersecurity landscape.

Impacted Technologies

VendorProductVersion(s)CPE
MatrixMatrix Specification
>= 0, < 1.16CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
1.8
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.42%
Probability of exploitation in next 30 days
EPSS Percentile
34.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0042 is in the 27th percentile among its peer group of 1,162 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

harborpatch availablevia llm_extracted
Fixed in: Spec 1.16, Room Version 12
netgearpatch availablevia llm_extracted
Fixed in: Room Version 12
phoenix_contactpatch availablevia llm_extracted
Fixed in: Matrix homeservers (new releases), Matrix Spec 1.16, Room Version 12
phoenix_contactpatch availablevia llm_extracted
Fixed in: Matrix Spec 1.16, Room Version 12

Vendor Advisories (4)

netgearllm-netgear-139951b2012be711HIGH

Coordinated Security Fix for Matrix Federation Protocol Vulnerabilities (Project Hydra)

Aug 14, 2025
phoenix_contactllm-phoenix_contact-02c70bfdec88110fHIGH

Project Hydra: Full Disclosure of State Resolution Security Improvements and Coordinated Release

Aug 14, 2025
harborllm-harbor-09615f464f385bddHIGH

High Severity Federation Protocol Vulnerabilities (Project Hydra)

Aug 11, 2025
phoenix_contactllm-phoenix_contact-a04c2165154073b4HIGH

Pre-disclosure: Upcoming coordinated security fix for all Matrix server implementations

Jul 16, 2025

References

github.com / matrix-org/matrix-spec/releases/tag/v1.16
github.com / Nheko-Reborn/nheko/issues/1931
matrix.org / blog/2025/08/project-hydra-improving-state-res
matrix.org / blog/2025/08/security-release