Vulnerabilities > Matrix

DATE CVE VULNERABILITY TITLE RISK
2023-06-06 CVE-2023-32683 Incorrect Authorization vulnerability in Matrix Synapse
Synapse is a Matrix protocol homeserver written in Python with the Twisted framework.
network
low complexity
matrix CWE-863
5.4
2023-05-26 CVE-2022-39335 Information Exposure vulnerability in Matrix Synapse
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation.
network
high complexity
matrix CWE-200
5.0
2023-05-26 CVE-2022-39374 Resource Exhaustion vulnerability in Matrix Synapse 1.62.0
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation.
network
low complexity
matrix CWE-400
6.5
2023-05-26 CVE-2023-32323 Improper Input Validation vulnerability in Matrix Synapse
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation.
network
low complexity
matrix CWE-20
4.3
2023-04-14 CVE-2023-29529 Unspecified vulnerability in Matrix Javascript SDK
matrix-js-sdk is the Matrix Client-Server SDK for JavaScript and TypeScript.
network
low complexity
matrix
5.3
2023-03-28 CVE-2022-36060 Unspecified vulnerability in Matrix React SDK
matrix-react-sdk is a Matrix chat protocol SDK for React Javascript.
network
low complexity
matrix
5.3
2023-03-28 CVE-2023-28427 Unspecified vulnerability in Matrix Javascript SDK
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript.
network
low complexity
matrix
8.2
2022-11-22 CVE-2022-41952 Missing Release of Resource after Effective Lifetime vulnerability in Matrix Synapse
Synapse before 1.52.0 with URL preview functionality enabled will attempt to generate URL previews for media stream URLs without properly limiting connection time.
network
low complexity
matrix CWE-772
5.3
2022-11-13 CVE-2022-3971 Improper Enforcement of Message or Data Structure vulnerability in Matrix IRC Bridge
A vulnerability was found in matrix-appservice-irc up to 0.35.1.
network
high complexity
matrix CWE-707
5.6
2022-09-29 CVE-2022-39252 Key Exchange without Entity Authentication vulnerability in Matrix Matrix-Rust-Sdk
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust, and matrix-sdk-crypto is the Matrix encryption library.
network
low complexity
matrix CWE-322
7.5