Matio is a specialized C library for reading and writing MATLAB data files, embedded across scientific computing, engineering simulation, and data-analysis workflows where binary format interchange is essential. Despite a narrow product scope, the library's position in research software and embedded toolchains gives it disproportionate reach, and its vulnerabilities skew strongly toward critical-severity outcomes reflecting the memory-safety demands of a binary-parsing implementation. The recurring weakness pattern—out-of-bounds reads, out-of-bounds writes, heap-based buffer overflows, and integer overflows—is characteristic of parsers handling untrusted, complex structured data without modern memory protections. Defenders tracking scientific and simulation pipelines should inventory Matio's presence and prioritize updates to the library wherever it is linked; current severity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Matio Project over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-50343CRITICAL An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not match the actual number of strings in the | Dec 30, 2025 | 9.8 | 31 | NO | NO |
CVE-2019-13107CRITICAL Multiple integer overflows exist in MATIO before 1.5.16, related to mat.c, mat4.c, mat5.c, mat73.c, and matvar_struct.c | Jun 30, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-9033CRITICAL An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read for the "Rank and Dimension" feature in the function ReadN | Feb 23, 2019 | 9.1 | 29 | NO | NO |
CVE-2019-9035CRITICAL An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read in the function ReadNextStructField() in mat5.c. | Feb 23, 2019 | 9.1 | 28 | NO | NO |
CVE-2019-9034CRITICAL An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read for a memcpy in the function ReadNextCell() in mat5.c. | Feb 23, 2019 | 9.1 | 28 | NO | NO |
CVE-2019-9030CRITICAL An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read in Mat_VarReadNextInfo5() in mat5.c. | Feb 23, 2019 | 9.1 | 28 | NO | NO |
CVE-2019-9028CRITICAL An issue was discovered in libmatio.a in matio (aka MAT File I/O Library) 1.5.13. There is a stack-based buffer over-read in the function InflateDimensions() in inflate.c when call | Feb 23, 2019 | 9.1 | 28 | NO | NO |
CVE-2020-19497HIGH Integer overflow vulnerability in Mat_VarReadNextInfo5 in mat5.c in tbeu matio (aka MAT File I/O Library) 1.5.17, allows attackers to cause a Denial of Service or possibly other un | Jul 21, 2021 | 8.8 | 27 | NO | NO |
CVE-2020-36428HIGH matio (aka MAT File I/O Library) 1.5.18 through 1.5.21 has a heap-based buffer overflow in ReadInt32DataDouble (called from ReadInt32Data and Mat_VarRead4). | Jul 20, 2021 | 8.8 | 27 | NO | NO |
CVE-2019-17533HIGH Mat_VarReadNextInfo4 in mat4.c in MATIO 1.5.17 omits a certain '\0' character, leading to a heap-based buffer over-read in strdup_vprintf when uninitialized memory is accessed. | Oct 13, 2019 | 8.2 | 27 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Matio Project.
Media articles that mention a CVE ID that affects a product developed by Matio Project — matched by CVE ID, not by vendor name.