Urgent Security Update for Matrix: High-Severity Vulnerabilities Patched

2025-07-17
Urgent Security Update for Matrix: High-Severity Vulnerabilities Patched

The Matrix team has identified and patched two high-severity protocol vulnerabilities (CVE-2025-49090 and another yet-to-be-assigned CVE) that could lead to unexpected state resets in Matrix servers. A coordinated security release across all Matrix server implementations is planned for July 22nd, 2025, at 17:00 UTC (version 1.16, room version 12). This update requires upgrading existing rooms. Users running Matrix servers are urged to upgrade as soon as possible. Client developers should review MSC4291 and update their clients to support the new room ID format and creator privileges.

Development