VendorsMatrixjavascript_sdkany version
Vulnerabilities

Matrix Javascript SDK any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2021-44538
The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can construct a crafted sequence of messages to manipulate the state of the receiver's session in such a way that, for some buffer sizes, a buffer overflow happens on a call to olm_session_describe. Furthermore, safe buffer sizes were undocumented. The overflow content is partially controllable by the attacker and limited to ASCII spaces and digits. The known affected products are Element Web And SchildiChat Web.
Published 2021-12-14 · Modified
9.8EPSS 0.019
CVE-2022-39250
Matrix JavaScript SDK vulnerable to key/device identifier confusion in SAS verification
Published 2022-09-29 · Modified
8.6EPSS 0.010
CVE-2022-39251
Matrix Javascript SDK vulnerable to Olm/Megolm protocol confusion
Published 2022-09-28 · Modified
8.6EPSS 0.010
CVE-2023-28427
Prototype pollution in matrix-js-sdk
Published 2023-03-28 · Modified
8.2EPSS 0.012
CVE-2022-36059
Prototype pollution in matrix-js-sdk
Published 2023-03-28 · Modified
8.2EPSS 0.009
CVE-2022-39249
Matrix Javascript SDK vulnerable to impersonation via forwarded Megolm sessions
Published 2022-09-28 · Modified
7.5EPSS 0.011
CVE-2021-40823
A logic error in the room key sharing functionality of matrix-js-sdk (aka Matrix Javascript SDK) before 12.4.1 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by affected Matrix clients participating in that room. This allows the homeserver to decrypt end-to-end encrypted messages sent by affected clients.
Published 2021-09-13 · Modified
5.9EPSS 0.007
CVE-2022-39236
Matrix Javascript SDK improper beacon events can cause availability issues
Published 2022-09-28 · Modified
5.3EPSS 0.011
CVE-2023-29529
matrix-js-sdk vulnerable to invisible eavesdropping in group calls
Published 2023-04-14 · Modified
5.3EPSS 0.005
CVE-2024-42369
A room with itself as a its predecessor will freeze matrix-js-sdk
Published 2024-08-20 · Analyzed
5.3EPSS 0.005