CVE-2025-49090
The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L
- EPSS probability
- 0.44%
- CWE
- CWE-642
- Published
- 2025-10-02
- Last modified
- 2026-03-13
Affected products
- Matrix Matrix specification
Weakness type
Related vulnerabilities
- CVE-2026-78655 — Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session
- CVE-2024-58265 — The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a...
- CVE-2025-54566 — hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to...
- CVE-2024-8754 — External Control of Critical State Data in GitLab
- CVE-2024-22387 — External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000...
- CVE-2023-0575 — Remote Code Execution
- CVE-2022-22154 — Junos Fusion: A Satellite Device can be controlled by rewiring it to a foreign AD causing a DoS
- CVE-2020-27872 — This vulnerability allows network-adjacent attackers to bypass authentication on affected...