Matrix is a decentralized messaging and collaboration platform whose vulnerability footprint centers on its core server and client libraries, components that sit at the foundation of open-source instant-messaging and federated communication deployments. The exposure recurs across products including the Synapse homeserver, JavaScript SDK, IRC bridge, identity server, and end-to-end encryption library, and concentrates in weakness classes including improper input validation, authentication flaws, key-exchange failures, and resource-consumption issues that are characteristic of protocol implementation and cryptographic systems. Vulnerabilities affecting the vendor reach serious severity at a meaningful rate, reflecting the security-sensitive role these components play in federated identity, encryption, and message routing. Defenders should monitor this vendor's security advisories closely, particularly for the widely deployed Synapse server, and prioritize patching of authentication and cryptographic defects in environments where Matrix serves as the underlying communication fabric. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Matrix over time
Signals from CVEs in this vendor scope (82 CVEs).
82 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44538CRITICAL The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. T | Dec 14, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-34813CRITICAL Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an Olm encrypted room key backup from the homeserver) because | Jun 16, 2021 | 9.8 | 30 | NO | NO |
CVE-2019-18835CRITICAL Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not com | Nov 8, 2019 | 9.8 | 30 | NO | NO |
CVE-2023-43656CRITICAL matrix-hookshot is a Matrix bot for connecting to external services like GitHub, GitLab, JIRA, and more. Instances that have enabled transformation functions (those that have `gene | Sep 27, 2023 | 9.0 | 28 | NO | NO |
CVE-2022-29166HIGH matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate a Matrix user into executing IRC commands by having them re | May 5, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-39203HIGH matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. Attackers can specify a specific string of characters, which would confuse the bridge into combining an attac | Sep 13, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-36009HIGH gomatrixserverlib is a Go library for matrix protocol federation. Dendrite is a Matrix homeserver written in Go, an alternative to Synapse. The power level parsing within gomatrixs | Aug 19, 2022 | 8.8 | 27 | NO | NO |
CVE-2018-16515HIGH Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation | Sep 18, 2018 | 8.8 | 27 | NO | NO |
CVE-2025-30355HIGH Synapse is an open source Matrix homeserver implementation. A malicious server can craft events which, when received, prevent Synapse version up to 1.127.0 from federating with oth | Mar 27, 2025 | 7.5 | 26 | NO | NO |
CVE-2023-38690CRITICAL matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with newlines which would not be properly parsed. This would mea | Aug 4, 2023 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (82 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Matrix.
Media articles that mention a CVE ID that affects a product developed by Matrix — matched by CVE ID, not by vendor name.