漏洞关键信息 Title Weak server key generation method Severity Critical CVE ID CVE-2026-24044 Affected Package matrix-stack (Helm) Affected Versions < 25.12.2 Patched Version 25.12.2 Impact The ESS Community Helm Chart secrets initialization hook (using matrix-tools container before 0.5.7) uses an insecure Matrix server key generation method, allowing network attackers to potentially recreate the same key pair, enabling them to impersonate the victim server. This impacts the confidentiality, integrity, and availability of rooms with a vulnerable server. Patches Fixed in matrix-tools 0.5.7, released as part of ESS Community Helm Chart 25.12.1. matrix-tools 0.5.8 and Synapse 1.144.0-ess.2 handle key generation issues in affected deployments. Workarounds None. Vulnerability Check Use the provided shell script to check if your ESS Synapse hostname is vulnerable.