CVE-2026-24044

Source
https://cve.org/CVERecord?id=CVE-2026-24044
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24044.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-24044
Aliases
  • GHSA-qwcj-h6m8-vp6q
Downstream
Related
Published
2026-02-12T19:06:12.998Z
Modified
2026-04-10T05:40:44.906088Z
Severity
  • 9.2 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
ESS Community Helm Chart has a weak server key generation method
Details

Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Community Helm Chart secrets initialization hook (using matrix-tools container before 0.5.7) is using an insecure Matrix server key generation method, allowing network attackers to potentially recreate the same key pair, allowing them to impersonate the victim server. The secret is generated by the secrets initialization hook, in the ESS Community Helm Chart values, if both initSecrets.enabled is not set to false and synapse.signingKey is not defined. Given a server key in Matrix authenticates both requests originating from and events constructed on a given server, this potentially impacts confidentiality, integrity and availability of rooms which have a vulnerable server present as a member. The confidentiality of past conversations in end-to-end encrypted rooms is not impacted. The key generation issue was fixed in matrix-tools 0.5.7, released as part of ESS Community Helm Chart 25.12.1.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24044.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-336"
    ]
}
References

Affected packages

Git / github.com/element-hq/ess-helm

Affected ranges

Type
GIT
Repo
https://github.com/element-hq/ess-helm
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*
0.1.0
0.10.0
0.10.1
0.11.0
0.11.1
0.11.2
0.11.3
0.12.0
0.2.0
0.3.0
0.3.1
0.4.0
0.4.1
0.5.0
0.6.0
0.6.1
0.7.0
0.7.1
0.7.2
0.7.3
0.8.0
0.9.0
25.*
25.04.01
25.10.0
25.10.1
25.10.2
25.10.3
25.11.0
25.11.1
25.12.0
25.6.0
25.6.1
25.6.2
25.7.0
25.8.0
25.8.1
25.8.2
25.8.3
25.9.0
25.9.1
25.9.2
25.9.3
matrix-tools-0.*
matrix-tools-0.1.0
matrix-tools-0.2.0
matrix-tools-0.3.4
matrix-tools-0.3.5
matrix-tools-0.5.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24044.json"