CVE-2025-49090
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-10-02
Last updated on: 2025-10-06
Assigner: MITRE
Description
Description
The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ejabberd | ejabberd | * |
| tuwunel | tuwunel | * |
| matrix | matrix | 1.16 |
| rocket.chat | rocket.chat | * |
| continuwuity | continuwuity | * |
| element | element | * |
| conduit | conduit | * |
| dendrite | dendrite | * |
| synapse | synapse | * |
| synapse_pro | synapse_pro | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-642 | The product stores security-critical state information about its users, or the product itself, in a location that is accessible to unauthorized actors. |