Vulnerabilidades en matrix-org

85 resultados
Análisis Vexday

O ecossistema matrix-org acumula 80 CVEs catalogadas, com 2 classificadas como críticas e nenhuma atualmente registrada no catálogo CISA KEV, posicionando o vendor abaixo da média geral de exploração ativa do catálogo. A ausência de provas de conceito públicas e de novos registros nos últimos 90 dias sugere um ritmo de descoberta baixo no período recente, embora o histórico acumulado mereça acompanhamento contínuo. A falha mais prevalente é do tipo CWE-287 (falhas de autenticação), o que indica uma área estrutural de risco que equipes de segurança devem priorizar em revisões de configuração e controle de acesso. A CVE mais perigosa ativa no momento é CVE-2020-26257, com score EPSS de 0,0236, sinalizando probabilidade de exploração relativamente baixa, mas que não deve ser descartada em ambientes que ainda não aplicaram as correções correspondentes.

CVE-2023-37259MEDIUMCross site scripting in Export Chat featureEPSS 0.5%CVE-2024-42347HIGHURL preview setting for a room is controllable by the homeserver in matrix-react-sdkEPSS 0.4%CVE-2025-66622LOWmatrix-sdk-base is vulnerable to DoS via custom m.room.join_rules event valuesEPSS 0.4%CVE-2025-59047LOWmatrix-sdk-base has panic in the `RoomMember::normalized_power_level()` methodEPSS 0.4%CVE-2025-27146LOWMatrix IRC Bridge allows IRC command injection to own puppeted userEPSS 0.4%CVE-2024-52505MEDIUMmatrix-appservice-irc allows IRC Command injection in provisioning APIEPSS 0.4%CVE-2021-32622MEDIUMFile upload local preview can run embedded scripts after user interactionEPSS 0.4%CVE-2025-48937MEDIUMmatrix-sdk-crypto vulnerable to sender of encrypted events being spoofed by homeserver administratorEPSS 0.4%CVE-2023-41335LOWTemporary storage of plaintext passwords during password changes in matrix synapseEPSS 0.4%CVE-2022-39200HIGHSignature checks not applied to some retrieved missing eventsEPSS 0.4%CVE-2024-52594MEDIUMServer-Side Request Forgery (SSRF) on redirects and federation in gomatrixserverlibEPSS 0.3%CVE-2026-63096MEDIUMDendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download EndpointEPSS 0.3%CVE-2026-63095HIGHDendrite 0.13.8 Improper Authorization via POST account/3pid/delete EndpointEPSS 0.3%CVE-2023-43656MEDIUMSandbox escape for instances that have enabled transformation functions in matrix-hookshotEPSS 0.3%CVE-2024-40648MEDIUM`UserIdentity::is_verified` not checking verification status of own user identity while performing the check in matrix-rust-sdkEPSS 0.3%CVE-2025-53549MEDIUMMatrix Rust SDK allows SQL injection in the EventCache implementationEPSS 0.3%CVE-2026-63097MEDIUMDendrite 0.13.8 syncapi /context Endpoint Post-Leave State ExposureEPSS 0.3%CVE-2023-38686CRITICALSydent does not verify email server certificatesEPSS 0.3%CVE-2025-59160LOWmatrix-js-sdk has insufficient validation when considering a room to be upgraded by anotherEPSS 0.2%CVE-2026-45056MEDIUMMatrix Rust SDK: Sender-binding gaps in to-device and room-key attributionEPSS 0.2%