Intel

AIKIDO-2025-10816

maunium.net/go/mautrix is vulnerable to Allocation of Resources Without Limits or Throttling

Allocation of Resources Without Limits or Throttling Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 18, 2025

25

Low Risk

This Affects:

GOmaunium.net/go/mautrix
0.9.6 - 0.25.2
Fixed in 0.26.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a Denial of Service (DoS) attack due to missing size limits on responses received from servers. An attacker could exploit this vulnerability by posing as a malicious server and sending an excessively large response, potentially leading to resource exhaustion and service unavailability for clients.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

maunium.net/go/mautrix is vulnerable to Allocation of Resources Without Limits or Throttling in versions 0.9.6 - 0.25.2.

How to fix this

Upgrade the maunium.net/go/mautrix library to the patch version.