Urgent Security Update for Matrix: High-Severity Vulnerabilities Patched

2025-07-17
Urgent Security Update for Matrix: High-Severity Vulnerabilities Patched

The Matrix team has identified and patched two high-severity protocol vulnerabilities (CVE-2025-49090 and another yet-to-be-assigned CVE) that could lead to unexpected state resets in Matrix servers. A coordinated security release across all Matrix server implementations is planned for July 22nd, 2025, at 17:00 UTC (version 1.16, room version 12). This update requires upgrading existing rooms. Users running Matrix servers are urged to upgrade as soon as possible. Client developers should review MSC4291 and update their clients to support the new room ID format and creator privileges.

Read more
Development

Matrix 1.15 Released: Next-Gen Authentication & Improved Room Summaries

2025-06-26
Matrix 1.15 Released: Next-Gen Authentication & Improved Room Summaries

Matrix 1.15 is here, boasting improvements to authentication, room summaries, and rich topics! This release incorporates 10 MSCs, highlighting the implementation of a next-generation authentication system – a significant step towards Matrix 2.0. New features also include enhanced room summaries, providing clients with richer room information, and support for rich text in room topics. These improvements enhance Matrix's security, user experience, and functionality.

Read more
Development Room Summaries

Matrix.org Upgrading to Next-Gen Authentication

2025-04-02
Matrix.org Upgrading to Next-Gen Authentication

On April 7th, 2025, at 7 AM UTC, Matrix.org will migrate its authentication system to MAS (Matrix Authentication Service) for next-generation authentication. This will involve up to one hour of downtime but brings a revamped account management interface, improved security (credentials only visible to your server), and a better registration experience. The upgrade utilizes OAuth 2.0/OIDC and paves the way for features like QR code login, opening new possibilities for Matrix applications.

Read more
Development

Matrix Foundation Faces Funding Crisis, Threatening Open Source Communication Protocol

2025-02-20
Matrix Foundation Faces Funding Crisis, Threatening Open Source Communication Protocol

The Matrix.org Foundation, responsible for maintaining the open-source communication protocol Matrix, is facing a severe funding shortage. Despite a successful 2024 and a Matrix Conference celebrating 10 years of Matrix, the Foundation is operating on a tight budget and faces existential threats. The Foundation's work in maintaining the Matrix specification, ensuring its security and interoperability, is crucial. Without sufficient funding, these core functions are at risk, potentially leading to fragmentation of the protocol. The Foundation is urgently seeking funding to maintain critical programs and avoid shutting down its bridging services, calling on individuals, organizations, and investors to help preserve this decentralized, end-to-end encrypted communication network.

Read more