matrix-sdk-base
Activity
- Latest release
- 3mo ago
- Total releases
- 23
- Cadence
- ~2 months
- Last 12 months
- 5
Details
- License
- Apache-2.0
- First release
- May 26, 2020
| Version | Released | |
|---|---|---|
0.18.0
unknown
|
0.18.0
unknown
Dependencies (39)
+ 31 more |
|
0.16.1
unknown
|
0.16.1
unknown
Dependencies (39)
+ 31 more |
|
0.17.0
unknown
|
0.17.0
unknown
Dependencies (39)
+ 31 more |
|
0.16.0
unknown
|
0.16.0
unknown
Dependencies (39)
+ 31 more |
|
0.15.0
unknown
yanked
1 CVE
CVE-2025-66622
GHSA-jj6p-3m75-g2p3
RUSTSEC-2025-0135
Dec 08, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
Network
Low
None
The matrix-sdk-base crate is unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. PatchesThe issue is fixed in matrix-sdk-base 0.16.0. WorkaroundsUsers can leave affected rooms on another client to mitigate the issue. ReferencesThe issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924. Fixed in
0.16.0
References
Updated Dec 09, 2025 · Source: OSV.dev |
0.15.0
unknown
yanked
Dependencies (39)
+ 31 more |
|
0.14.1
unknown
1 CVE
CVE-2025-66622
GHSA-jj6p-3m75-g2p3
RUSTSEC-2025-0135
Dec 08, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
Network
Low
None
The matrix-sdk-base crate is unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. PatchesThe issue is fixed in matrix-sdk-base 0.16.0. WorkaroundsUsers can leave affected rooms on another client to mitigate the issue. ReferencesThe issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924. Fixed in
0.16.0
References
Updated Dec 09, 2025 · Source: OSV.dev |
0.14.1
unknown
Dependencies (39)
+ 31 more |
|
0.14.0
unknown
2 CVEs
CVE-2025-66622
GHSA-jj6p-3m75-g2p3
RUSTSEC-2025-0135
Dec 08, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
Network
Low
None
The matrix-sdk-base crate is unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. PatchesThe issue is fixed in matrix-sdk-base 0.16.0. WorkaroundsUsers can leave affected rooms on another client to mitigate the issue. ReferencesThe issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924. Fixed in
0.16.0
References
Updated Dec 09, 2025 · Source: OSV.dev
CVE-2025-59047
GHSA-qhj8-q5r6-8q6j
RUSTSEC-2025-0000
RUSTSEC-2025-0065
Sep 11, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
Network
Low
None
None
In matrix-sdk-base before 0.14.1, calling the PatchesThe issue is fixed in matrix-sdk-base 0.14.1. WorkaroundsThe affected method isn’t used internally, so avoiding calling Fixed in
0.14.1
References
Updated Sep 11, 2025 · Source: OSV.dev |
0.14.0
unknown
Dependencies (38)
+ 30 more |
|
0.13.0
unknown
2 CVEs
CVE-2025-66622
GHSA-jj6p-3m75-g2p3
RUSTSEC-2025-0135
Dec 08, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
Network
Low
None
The matrix-sdk-base crate is unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. PatchesThe issue is fixed in matrix-sdk-base 0.16.0. WorkaroundsUsers can leave affected rooms on another client to mitigate the issue. ReferencesThe issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924. Fixed in
0.16.0
References
Updated Dec 09, 2025 · Source: OSV.dev
CVE-2025-59047
GHSA-qhj8-q5r6-8q6j
RUSTSEC-2025-0000
RUSTSEC-2025-0065
Sep 11, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
Network
Low
None
None
In matrix-sdk-base before 0.14.1, calling the PatchesThe issue is fixed in matrix-sdk-base 0.14.1. WorkaroundsThe affected method isn’t used internally, so avoiding calling Fixed in
0.14.1
References
Updated Sep 11, 2025 · Source: OSV.dev |
0.13.0
unknown
Dependencies (36)
+ 28 more |
|
0.12.0
unknown
2 CVEs
CVE-2025-66622
GHSA-jj6p-3m75-g2p3
RUSTSEC-2025-0135
Dec 08, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
Network
Low
None
The matrix-sdk-base crate is unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. PatchesThe issue is fixed in matrix-sdk-base 0.16.0. WorkaroundsUsers can leave affected rooms on another client to mitigate the issue. ReferencesThe issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924. Fixed in
0.16.0
References
Updated Dec 09, 2025 · Source: OSV.dev
CVE-2025-59047
GHSA-qhj8-q5r6-8q6j
RUSTSEC-2025-0000
RUSTSEC-2025-0065
Sep 11, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
Network
Low
None
None
In matrix-sdk-base before 0.14.1, calling the PatchesThe issue is fixed in matrix-sdk-base 0.14.1. WorkaroundsThe affected method isn’t used internally, so avoiding calling Fixed in
0.14.1
References
Updated Sep 11, 2025 · Source: OSV.dev |
0.12.0
unknown
Dependencies (35)
+ 27 more |
|
0.11.0
unknown
2 CVEs
CVE-2025-66622
GHSA-jj6p-3m75-g2p3
RUSTSEC-2025-0135
Dec 08, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
Network
Low
None
The matrix-sdk-base crate is unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. PatchesThe issue is fixed in matrix-sdk-base 0.16.0. WorkaroundsUsers can leave affected rooms on another client to mitigate the issue. ReferencesThe issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924. Fixed in
0.16.0
References
Updated Dec 09, 2025 · Source: OSV.dev
CVE-2025-59047
GHSA-qhj8-q5r6-8q6j
RUSTSEC-2025-0000
RUSTSEC-2025-0065
Sep 11, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
Network
Low
None
None
In matrix-sdk-base before 0.14.1, calling the PatchesThe issue is fixed in matrix-sdk-base 0.14.1. WorkaroundsThe affected method isn’t used internally, so avoiding calling Fixed in
0.14.1
References
Updated Sep 11, 2025 · Source: OSV.dev |
0.11.0
unknown
Dependencies (35)
+ 27 more |
|
0.10.0
unknown
2 CVEs
CVE-2025-66622
GHSA-jj6p-3m75-g2p3
RUSTSEC-2025-0135
Dec 08, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
Network
Low
None
The matrix-sdk-base crate is unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. PatchesThe issue is fixed in matrix-sdk-base 0.16.0. WorkaroundsUsers can leave affected rooms on another client to mitigate the issue. ReferencesThe issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924. Fixed in
0.16.0
References
Updated Dec 09, 2025 · Source: OSV.dev
CVE-2025-59047
GHSA-qhj8-q5r6-8q6j
RUSTSEC-2025-0000
RUSTSEC-2025-0065
Sep 11, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
Network
Low
None
None
In matrix-sdk-base before 0.14.1, calling the PatchesThe issue is fixed in matrix-sdk-base 0.14.1. WorkaroundsThe affected method isn’t used internally, so avoiding calling Fixed in
0.14.1
References
Updated Sep 11, 2025 · Source: OSV.dev |
0.10.0
unknown
Dependencies (35)
+ 27 more |
|
0.9.0
unknown
2 CVEs
CVE-2025-66622
GHSA-jj6p-3m75-g2p3
RUSTSEC-2025-0135
Dec 08, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
Network
Low
None
The matrix-sdk-base crate is unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. PatchesThe issue is fixed in matrix-sdk-base 0.16.0. WorkaroundsUsers can leave affected rooms on another client to mitigate the issue. ReferencesThe issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924. Fixed in
0.16.0
References
Updated Dec 09, 2025 · Source: OSV.dev
CVE-2025-59047
GHSA-qhj8-q5r6-8q6j
RUSTSEC-2025-0000
RUSTSEC-2025-0065
Sep 11, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
Network
Low
None
None
In matrix-sdk-base before 0.14.1, calling the PatchesThe issue is fixed in matrix-sdk-base 0.14.1. WorkaroundsThe affected method isn’t used internally, so avoiding calling Fixed in
0.14.1
References
Updated Sep 11, 2025 · Source: OSV.dev |
0.9.0
unknown
Dependencies (35)
+ 27 more |
|
0.8.0
unknown
2 CVEs
CVE-2025-66622
GHSA-jj6p-3m75-g2p3
RUSTSEC-2025-0135
Dec 08, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
Network
Low
None
The matrix-sdk-base crate is unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. PatchesThe issue is fixed in matrix-sdk-base 0.16.0. WorkaroundsUsers can leave affected rooms on another client to mitigate the issue. ReferencesThe issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924. Fixed in
0.16.0
References
Updated Dec 09, 2025 · Source: OSV.dev
CVE-2025-59047
GHSA-qhj8-q5r6-8q6j
RUSTSEC-2025-0000
RUSTSEC-2025-0065
Sep 11, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
Network
Low
None
None
In matrix-sdk-base before 0.14.1, calling the PatchesThe issue is fixed in matrix-sdk-base 0.14.1. WorkaroundsThe affected method isn’t used internally, so avoiding calling Fixed in
0.14.1
References
Updated Sep 11, 2025 · Source: OSV.dev |
0.8.0
unknown
Dependencies (35)
+ 27 more |
|
0.7.0
unknown
2 CVEs
CVE-2025-66622
GHSA-jj6p-3m75-g2p3
RUSTSEC-2025-0135
Dec 08, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
Network
Low
None
The matrix-sdk-base crate is unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. PatchesThe issue is fixed in matrix-sdk-base 0.16.0. WorkaroundsUsers can leave affected rooms on another client to mitigate the issue. ReferencesThe issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924. Fixed in
0.16.0
References
Updated Dec 09, 2025 · Source: OSV.dev
CVE-2025-59047
GHSA-qhj8-q5r6-8q6j
RUSTSEC-2025-0000
RUSTSEC-2025-0065
Sep 11, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
Network
Low
None
None
In matrix-sdk-base before 0.14.1, calling the PatchesThe issue is fixed in matrix-sdk-base 0.14.1. WorkaroundsThe affected method isn’t used internally, so avoiding calling Fixed in
0.14.1
References
Updated Sep 11, 2025 · Source: OSV.dev |
0.7.0
unknown
Dependencies (29)
+ 21 more |
|
0.6.1
unknown
2 CVEs
CVE-2025-66622
GHSA-jj6p-3m75-g2p3
RUSTSEC-2025-0135
Dec 08, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
Network
Low
None
The matrix-sdk-base crate is unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. PatchesThe issue is fixed in matrix-sdk-base 0.16.0. WorkaroundsUsers can leave affected rooms on another client to mitigate the issue. ReferencesThe issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924. Fixed in
0.16.0
References
Updated Dec 09, 2025 · Source: OSV.dev
CVE-2025-59047
GHSA-qhj8-q5r6-8q6j
RUSTSEC-2025-0000
RUSTSEC-2025-0065
Sep 11, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
Network
Low
None
None
In matrix-sdk-base before 0.14.1, calling the PatchesThe issue is fixed in matrix-sdk-base 0.14.1. WorkaroundsThe affected method isn’t used internally, so avoiding calling Fixed in
0.14.1
References
Updated Sep 11, 2025 · Source: OSV.dev |
0.6.1
unknown
Dependencies (26)
+ 18 more |
|
0.6.0
unknown
2 CVEs
CVE-2025-66622
GHSA-jj6p-3m75-g2p3
RUSTSEC-2025-0135
Dec 08, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
Network
Low
None
The matrix-sdk-base crate is unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. PatchesThe issue is fixed in matrix-sdk-base 0.16.0. WorkaroundsUsers can leave affected rooms on another client to mitigate the issue. ReferencesThe issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924. Fixed in
0.16.0
References
Updated Dec 09, 2025 · Source: OSV.dev
CVE-2025-59047
GHSA-qhj8-q5r6-8q6j
RUSTSEC-2025-0000
RUSTSEC-2025-0065
Sep 11, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
Network
Low
None
None
In matrix-sdk-base before 0.14.1, calling the PatchesThe issue is fixed in matrix-sdk-base 0.14.1. WorkaroundsThe affected method isn’t used internally, so avoiding calling Fixed in
0.14.1
References
Updated Sep 11, 2025 · Source: OSV.dev |
0.6.0
unknown
Dependencies (26)
+ 18 more |
|
0.5.1
unknown
2 CVEs
CVE-2025-66622
GHSA-jj6p-3m75-g2p3
RUSTSEC-2025-0135
Dec 08, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
Network
Low
None
The matrix-sdk-base crate is unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. PatchesThe issue is fixed in matrix-sdk-base 0.16.0. WorkaroundsUsers can leave affected rooms on another client to mitigate the issue. ReferencesThe issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924. Fixed in
0.16.0
References
Updated Dec 09, 2025 · Source: OSV.dev
CVE-2025-59047
GHSA-qhj8-q5r6-8q6j
RUSTSEC-2025-0000
RUSTSEC-2025-0065
Sep 11, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
Network
Low
None
None
In matrix-sdk-base before 0.14.1, calling the PatchesThe issue is fixed in matrix-sdk-base 0.14.1. WorkaroundsThe affected method isn’t used internally, so avoiding calling Fixed in
0.14.1
References
Updated Sep 11, 2025 · Source: OSV.dev |
0.5.1
unknown
Dependencies (29)
+ 21 more |
|
0.5.0
unknown
2 CVEs
CVE-2025-66622
GHSA-jj6p-3m75-g2p3
RUSTSEC-2025-0135
Dec 08, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
Network
Low
None
The matrix-sdk-base crate is unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. PatchesThe issue is fixed in matrix-sdk-base 0.16.0. WorkaroundsUsers can leave affected rooms on another client to mitigate the issue. ReferencesThe issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924. Fixed in
0.16.0
References
Updated Dec 09, 2025 · Source: OSV.dev
CVE-2025-59047
GHSA-qhj8-q5r6-8q6j
RUSTSEC-2025-0000
RUSTSEC-2025-0065
Sep 11, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
Network
Low
None
None
In matrix-sdk-base before 0.14.1, calling the PatchesThe issue is fixed in matrix-sdk-base 0.14.1. WorkaroundsThe affected method isn’t used internally, so avoiding calling Fixed in
0.14.1
References
Updated Sep 11, 2025 · Source: OSV.dev |
0.5.0
unknown
Dependencies (22)
+ 14 more |
|
0.4.1
unknown
2 CVEs
CVE-2025-66622
GHSA-jj6p-3m75-g2p3
RUSTSEC-2025-0135
Dec 08, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
Network
Low
None
The matrix-sdk-base crate is unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. PatchesThe issue is fixed in matrix-sdk-base 0.16.0. WorkaroundsUsers can leave affected rooms on another client to mitigate the issue. ReferencesThe issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924. Fixed in
0.16.0
References
Updated Dec 09, 2025 · Source: OSV.dev
CVE-2025-59047
GHSA-qhj8-q5r6-8q6j
RUSTSEC-2025-0000
RUSTSEC-2025-0065
Sep 11, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
Network
Low
None
None
In matrix-sdk-base before 0.14.1, calling the PatchesThe issue is fixed in matrix-sdk-base 0.14.1. WorkaroundsThe affected method isn’t used internally, so avoiding calling Fixed in
0.14.1
References
Updated Sep 11, 2025 · Source: OSV.dev |
0.4.1
unknown
Dependencies (28)
+ 20 more |
|
0.4.0
unknown
2 CVEs
CVE-2025-66622
GHSA-jj6p-3m75-g2p3
RUSTSEC-2025-0135
Dec 08, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
Network
Low
None
The matrix-sdk-base crate is unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. PatchesThe issue is fixed in matrix-sdk-base 0.16.0. WorkaroundsUsers can leave affected rooms on another client to mitigate the issue. ReferencesThe issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924. Fixed in
0.16.0
References
Updated Dec 09, 2025 · Source: OSV.dev
CVE-2025-59047
GHSA-qhj8-q5r6-8q6j
RUSTSEC-2025-0000
RUSTSEC-2025-0065
Sep 11, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
Network
Low
None
None
In matrix-sdk-base before 0.14.1, calling the PatchesThe issue is fixed in matrix-sdk-base 0.14.1. WorkaroundsThe affected method isn’t used internally, so avoiding calling Fixed in
0.14.1
References
Updated Sep 11, 2025 · Source: OSV.dev |
0.4.0
unknown
Dependencies (28)
+ 20 more |
|
0.3.0
unknown
2 CVEs
CVE-2025-66622
GHSA-jj6p-3m75-g2p3
RUSTSEC-2025-0135
Dec 08, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
Network
Low
None
The matrix-sdk-base crate is unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. PatchesThe issue is fixed in matrix-sdk-base 0.16.0. WorkaroundsUsers can leave affected rooms on another client to mitigate the issue. ReferencesThe issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924. Fixed in
0.16.0
References
Updated Dec 09, 2025 · Source: OSV.dev
CVE-2025-59047
GHSA-qhj8-q5r6-8q6j
RUSTSEC-2025-0000
RUSTSEC-2025-0065
Sep 11, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
Network
Low
None
None
In matrix-sdk-base before 0.14.1, calling the PatchesThe issue is fixed in matrix-sdk-base 0.14.1. WorkaroundsThe affected method isn’t used internally, so avoiding calling Fixed in
0.14.1
References
Updated Sep 11, 2025 · Source: OSV.dev |
0.3.0
unknown
Dependencies (28)
+ 20 more |
|
0.2.0
unknown
2 CVEs
CVE-2025-66622
GHSA-jj6p-3m75-g2p3
RUSTSEC-2025-0135
Dec 08, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
Network
Low
None
The matrix-sdk-base crate is unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. PatchesThe issue is fixed in matrix-sdk-base 0.16.0. WorkaroundsUsers can leave affected rooms on another client to mitigate the issue. ReferencesThe issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924. Fixed in
0.16.0
References
Updated Dec 09, 2025 · Source: OSV.dev
CVE-2025-59047
GHSA-qhj8-q5r6-8q6j
RUSTSEC-2025-0000
RUSTSEC-2025-0065
Sep 11, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
Network
Low
None
None
In matrix-sdk-base before 0.14.1, calling the PatchesThe issue is fixed in matrix-sdk-base 0.14.1. WorkaroundsThe affected method isn’t used internally, so avoiding calling Fixed in
0.14.1
References
Updated Sep 11, 2025 · Source: OSV.dev |
0.2.0
unknown
Dependencies (16)
+ 8 more |
|
0.1.0
unknown
2 CVEs
CVE-2025-66622
GHSA-jj6p-3m75-g2p3
RUSTSEC-2025-0135
Dec 08, 2025
matrix-sdk-base denial of service via custom m.room.join_rules event values
Low
Network
Low
None
The matrix-sdk-base crate is unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. PatchesThe issue is fixed in matrix-sdk-base 0.16.0. WorkaroundsUsers can leave affected rooms on another client to mitigate the issue. ReferencesThe issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924. Fixed in
0.16.0
References
Updated Dec 09, 2025 · Source: OSV.dev
CVE-2025-59047
GHSA-qhj8-q5r6-8q6j
RUSTSEC-2025-0000
RUSTSEC-2025-0065
Sep 11, 2025
matrix-sdk-base: Panic in the `RoomMember::normalized_power_level()` method
Low
Network
Low
None
None
In matrix-sdk-base before 0.14.1, calling the PatchesThe issue is fixed in matrix-sdk-base 0.14.1. WorkaroundsThe affected method isn’t used internally, so avoiding calling Fixed in
0.14.1
References
Updated Sep 11, 2025 · Source: OSV.dev |
0.1.0
unknown
Dependencies (14)
+ 6 more |