Known Vulnerabilities for Matrix by Squiz
Listed below are 6 of the newest known vulnerabilities associated with "Matrix" by "Squiz".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-63095 json | Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any auth... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-61465 json | ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the allowed memory allocation limit in matrix-backed operati... | Not Provided | 2026-07-11 | 2026-07-14 |
| CVE-2026-57963 json | An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS... | Not Provided | 2026-07-01 | 2026-07-01 |
| CVE-2026-53811 json | OpenClaw before 2026.5.7 contains a privilege escalation vulnerability in the Matrix allowFrom feature that allows authentica... | Not Provided | 2026-06-11 | 2026-06-11 |
| CVE-2026-50559 json | Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.... | Not Provided | 2026-06-19 | 2026-07-21 |
| CVE-2026-49140 json | Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel media download handler that a... | Not Provided | 2026-06-01 | 2026-07-14 |
| CVE-2026-45078 json | Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to ... | Not Provided | 2026-05-28 | 2026-05-29 |
| CVE-2026-45076 json | Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers can c... | Not Provided | 2026-05-28 | 2026-06-02 |
| CVE-2026-45003 json | OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC, and... | Not Provided | 2026-05-11 | 2026-05-11 |
| CVE-2026-44110 json | OpenClaw before 2026.4.15 contains an authorization bypass vulnerability in Matrix room control-command authorization that tr... | Not Provided | 2026-05-06 | 2026-05-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Squiz | Matrix | 5.5.5.0 | |||
| Application | Squiz | Matrix | 5.5.4.2 | |||
| Application | Squiz | Matrix | 5.5.4.1 | |||
| Application | Squiz | Matrix | 5.5.4.0 | |||
| Application | Squiz | Matrix | 5.5.3.3 | |||
| Application | Squiz | Matrix | 5.5.3.2 | |||
| Application | Squiz | Matrix | 5.5.3.1 | |||
| Application | Squiz | Matrix | 5.5.3.0 | |||
| Application | Squiz | Matrix | 5.5.2.4 | |||
| Application | Squiz | Matrix | 5.5.2.3 | |||
| Application | Squiz | Matrix | 5.5.2.2 | |||
| Application | Squiz | Matrix | 5.5.2.1 | |||
| Application | Squiz | Matrix | 5.5.2.0 | |||
| Application | Squiz | Matrix | 5.5.1.8 | |||
| Application | Squiz | Matrix | 5.5.1.7 | |||
| Application | Squiz | Matrix | 5.5.1.6 | |||
| Application | Squiz | Matrix | 5.5.1.5 | |||
| Application | Squiz | Matrix | 5.5.1.4 | |||
| Application | Squiz | Matrix | 5.5.1.3 | |||
| Application | Squiz | Matrix | 5.5.1.2 |