Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Matrix

First CVE: Feb 6, 2004Active for: 22 yearsTotal CVEs: 82
21.6
VTI Score
Low

Matrix is a decentralized messaging and collaboration platform whose vulnerability footprint centers on its core server and client libraries, components that sit at the foundation of open-source instant-messaging and federated communication deployments. The exposure recurs across products including the Synapse homeserver, JavaScript SDK, IRC bridge, identity server, and end-to-end encryption library, and concentrates in weakness classes including improper input validation, authentication flaws, key-exchange failures, and resource-consumption issues that are characteristic of protocol implementation and cryptographic systems. Vulnerabilities affecting the vendor reach serious severity at a meaningful rate, reflecting the security-sensitive role these components play in federated identity, encryption, and message routing. Defenders should monitor this vendor's security advisories closely, particularly for the widely deployed Synapse server, and prioritize patching of authentication and cryptographic defects in environments where Matrix serves as the underlying communication fabric. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
82
Total CVEs
More Total CVEs than 99% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Matrix over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 6, 2004
22 years ago
Most Recent CVE
Dec 9, 2025
227 days ago

Products(16 total)

Top CVEs

Signals from CVEs in this vendor scope (82 CVEs).

82 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-44538CRITICAL
The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. T
Dec 14, 20219.831NONO
CVE-2021-34813CRITICAL
Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because
Jun 16, 20219.830NONO
CVE-2019-18835CRITICAL
Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not com
Nov 8, 20199.830NONO
CVE-2023-43656CRITICAL
matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. Instances that have enabled transformation functions (those that have `gene
Sep 27, 20239.028NONO
CVE-2022-29166HIGH
matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate a Matrix user into executing IRC commands by having them re
May 5, 20228.828NONO
CVE-2022-39203HIGH
matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. Attackers can specify a specific string of characters, which would confuse the bridge into combining an attac
Sep 13, 20228.827NONO
CVE-2022-36009HIGH
gomatrixserverlib is a Go library for matrix protocol federation. Dendrite is a Matrix homeserver written in Go, an alternative to Synapse. The power level parsing within gomatrixs
Aug 19, 20228.827NONO
CVE-2018-16515HIGH
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation
Sep 18, 20188.827NONO
CVE-2025-30355HIGH
Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with oth
Mar 27, 20257.526NONO
CVE-2023-38690CRITICAL
matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with newlines which would not be properly parsed. This would mea
Aug 4, 20239.826NONO
View all 82 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products82 CVEs
56%
32%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network80 (97.6%)
Unknown1 (1.2%)
Physical0 (0.0%)
Adjacent Network1 (1.2%)
Attack Complexity
Low67 (81.7%)
High14 (17.1%)
Unknown1 (1.2%)
User Interaction
None71 (86.6%)
Unknown1 (1.2%)
Required10 (12.2%)
Privileges Required
Low27 (32.9%)
High2 (2.4%)
None52 (63.4%)
Unknown1 (1.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (82 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Matrix.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Matrix — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Matrix's Products

View all 3 CNAs →

Top CWEs