CVE-2025-49090: High severity matrix Matrix specification vulnerability
Published Oct 2, 2025
·Updated
The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution.
Affected Software
1 affected component
matrix Matrix specification<1.16
Event History
Aug 13, 2025
News Published
via The Register·09:15 AM
News Published
via The Register·09:20 AM
Oct 2, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-49090?
CVE-2025-49090 is considered a critical vulnerability due to its impact on state resolution within the Matrix specification.
2
How do I fix CVE-2025-49090?
To fix CVE-2025-49090, upgrade to Matrix specification version 1.16 or higher.
3
What systems are affected by CVE-2025-49090?
CVE-2025-49090 affects all applications utilizing the Matrix specification before version 1.16.
4
What are the implications of CVE-2025-49090?
The implications of CVE-2025-49090 include potential unauthorized access to chat room states due to deficient state resolution.
5
Is there a workaround for CVE-2025-49090?
There are no known effective workarounds for CVE-2025-49090; upgrading to a secure version is recommended.