matrix-sdk-crypto
Activity
- Latest release
- 3mo ago
- Total releases
- 23
- Cadence
- ~2 months
- Last 12 months
- 5
Details
- License
- Apache-2.0
- First release
- May 26, 2020
| Version | Released | |
|---|---|---|
0.18.0
unknown
|
0.18.0
unknown
Dependencies (49)
+ 41 more |
|
0.16.1
unknown
|
0.16.1
unknown
Dependencies (50)
+ 42 more |
|
0.17.0
unknown
|
0.17.0
unknown
Dependencies (49)
+ 41 more |
|
0.16.0
unknown
1 CVE
CVE-2026-45056
GHSA-wfq4-36m3-9g42
RUSTSEC-2026-0159
Jun 04, 2026
Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution
Medium
Network
Low
High
None
ImpactThe This could be exploited to spoof the sender of an encrypted to-device message, but only if the attacker colludes with (or is) the homeserver operator. PatchesThis issue is fixed in WorkaroundsThere are no known workarounds for the issue. ReferencesThis issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/6553. For more informationIf you have any questions or comments about this advisory, please email us at security at matrix.org. Fixed in
0.16.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
0.16.0
unknown
Dependencies (50)
+ 42 more |
|
0.15.0
unknown
yanked
1 CVE
CVE-2026-45056
GHSA-wfq4-36m3-9g42
RUSTSEC-2026-0159
Jun 04, 2026
Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution
Medium
Network
Low
High
None
ImpactThe This could be exploited to spoof the sender of an encrypted to-device message, but only if the attacker colludes with (or is) the homeserver operator. PatchesThis issue is fixed in WorkaroundsThere are no known workarounds for the issue. ReferencesThis issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/6553. For more informationIf you have any questions or comments about this advisory, please email us at security at matrix.org. Fixed in
0.16.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
0.15.0
unknown
yanked
Dependencies (50)
+ 42 more |
|
0.14.0
unknown
1 CVE
CVE-2026-45056
GHSA-wfq4-36m3-9g42
RUSTSEC-2026-0159
Jun 04, 2026
Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution
Medium
Network
Low
High
None
ImpactThe This could be exploited to spoof the sender of an encrypted to-device message, but only if the attacker colludes with (or is) the homeserver operator. PatchesThis issue is fixed in WorkaroundsThere are no known workarounds for the issue. ReferencesThis issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/6553. For more informationIf you have any questions or comments about this advisory, please email us at security at matrix.org. Fixed in
0.16.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
0.14.0
unknown
Dependencies (50)
+ 42 more |
|
0.13.0
unknown
1 CVE
CVE-2026-45056
GHSA-wfq4-36m3-9g42
RUSTSEC-2026-0159
Jun 04, 2026
Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution
Medium
Network
Low
High
None
ImpactThe This could be exploited to spoof the sender of an encrypted to-device message, but only if the attacker colludes with (or is) the homeserver operator. PatchesThis issue is fixed in WorkaroundsThere are no known workarounds for the issue. ReferencesThis issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/6553. For more informationIf you have any questions or comments about this advisory, please email us at security at matrix.org. Fixed in
0.16.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
0.13.0
unknown
Dependencies (49)
+ 41 more |
|
0.12.0
unknown
1 CVE
CVE-2026-45056
GHSA-wfq4-36m3-9g42
RUSTSEC-2026-0159
Jun 04, 2026
Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution
Medium
Network
Low
High
None
ImpactThe This could be exploited to spoof the sender of an encrypted to-device message, but only if the attacker colludes with (or is) the homeserver operator. PatchesThis issue is fixed in WorkaroundsThere are no known workarounds for the issue. ReferencesThis issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/6553. For more informationIf you have any questions or comments about this advisory, please email us at security at matrix.org. Fixed in
0.16.1
References
Updated Jun 04, 2026 · Source: OSV.dev |
0.12.0
unknown
Dependencies (49)
+ 41 more |
|
0.11.1
unknown
|
0.11.1
unknown
Dependencies (49)
+ 41 more |
|
0.11.0
unknown
1 CVE
CVE-2025-48937
RUSTSEC-2025-0041
GHSA-x958-rvg6-956w
Jun 11, 2025
matrix-sdk-crypto vulnerable to encrypted event sender spoofing by homeserver administrator
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
None
matrix-sdk-crypto versions 0.8.0 up to and including 0.11.0 does not correctly validate the sender of an encrypted event. Accordingly, a malicious homeserver operator can modify events served to clients, making those events appear to the recipient as if they were sent by another user. Although the CVSS score is 4.9 (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N), we consider this a High severity security issue. Fixed in
0.11.1
References Updated Jun 12, 2025 · Source: OSV.dev |
0.11.0
unknown
Dependencies (49)
+ 41 more |
|
0.10.0
unknown
1 CVE
CVE-2025-48937
RUSTSEC-2025-0041
GHSA-x958-rvg6-956w
Jun 11, 2025
matrix-sdk-crypto vulnerable to encrypted event sender spoofing by homeserver administrator
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
None
matrix-sdk-crypto versions 0.8.0 up to and including 0.11.0 does not correctly validate the sender of an encrypted event. Accordingly, a malicious homeserver operator can modify events served to clients, making those events appear to the recipient as if they were sent by another user. Although the CVSS score is 4.9 (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N), we consider this a High severity security issue. Fixed in
0.11.1
References Updated Jun 12, 2025 · Source: OSV.dev |
0.10.0
unknown
Dependencies (49)
+ 41 more |
|
0.9.0
unknown
1 CVE
CVE-2025-48937
RUSTSEC-2025-0041
GHSA-x958-rvg6-956w
Jun 11, 2025
matrix-sdk-crypto vulnerable to encrypted event sender spoofing by homeserver administrator
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
None
matrix-sdk-crypto versions 0.8.0 up to and including 0.11.0 does not correctly validate the sender of an encrypted event. Accordingly, a malicious homeserver operator can modify events served to clients, making those events appear to the recipient as if they were sent by another user. Although the CVSS score is 4.9 (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N), we consider this a High severity security issue. Fixed in
0.11.1
References Updated Jun 12, 2025 · Source: OSV.dev |
0.9.0
unknown
Dependencies (47)
+ 39 more |
|
0.8.0
unknown
1 CVE
CVE-2025-48937
RUSTSEC-2025-0041
GHSA-x958-rvg6-956w
Jun 11, 2025
matrix-sdk-crypto vulnerable to encrypted event sender spoofing by homeserver administrator
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
None
High
None
matrix-sdk-crypto versions 0.8.0 up to and including 0.11.0 does not correctly validate the sender of an encrypted event. Accordingly, a malicious homeserver operator can modify events served to clients, making those events appear to the recipient as if they were sent by another user. Although the CVSS score is 4.9 (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N), we consider this a High severity security issue. Fixed in
0.11.1
References Updated Jun 12, 2025 · Source: OSV.dev |
0.8.0
unknown
Dependencies (46)
+ 38 more |
|
0.7.2
unknown
1 CVE
CVE-2024-52813
GHSA-r5vf-wf4h-82gg
RUSTSEC-2024-0434
Jan 07, 2025
matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactVersions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK to overlook such changes. Patchesmatrix-sdk-crypto 0.8.0 adds a new References
Fixed in
0.8.0
References Updated Jan 22, 2025 · Source: OSV.dev |
0.7.2
unknown
Dependencies (43)
+ 35 more |
|
0.7.1
unknown
2 CVEs
CVE-2024-52813
GHSA-r5vf-wf4h-82gg
RUSTSEC-2024-0434
Jan 07, 2025
matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactVersions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK to overlook such changes. Patchesmatrix-sdk-crypto 0.8.0 adds a new References
Fixed in
0.8.0
References Updated Jan 22, 2025 · Source: OSV.dev
CVE-2024-40648
GHSA-4qg4-cvh2-crgg
RUSTSEC-2024-0356
Jul 18, 2024
matrix-sdk-crypto's `UserIdentity::is_verified` not checking verification status of own user identity while performing the check
Medium
Network
Low
None
None
The ImpactIf the method is used to decide whether to perform sensitive operations towards a user identity, a malicious homeserver could manipulate the outcome in order to make the identity appear trusted. This is not a typical usage of the method, which lowers the impact. The method itself is not used inside the PatchesThe 0.7.2 release of the WorkaroundsNone. Fixed in
0.7.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.7.1
unknown
Dependencies (43)
+ 35 more |
|
0.7.0
unknown
3 CVEs
CVE-2024-52813
GHSA-r5vf-wf4h-82gg
RUSTSEC-2024-0434
Jan 07, 2025
matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactVersions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK to overlook such changes. Patchesmatrix-sdk-crypto 0.8.0 adds a new References
Fixed in
0.8.0
References Updated Jan 22, 2025 · Source: OSV.dev
CVE-2024-40648
GHSA-4qg4-cvh2-crgg
RUSTSEC-2024-0356
Jul 18, 2024
matrix-sdk-crypto's `UserIdentity::is_verified` not checking verification status of own user identity while performing the check
Medium
Network
Low
None
None
The ImpactIf the method is used to decide whether to perform sensitive operations towards a user identity, a malicious homeserver could manipulate the outcome in order to make the identity appear trusted. This is not a typical usage of the method, which lowers the impact. The method itself is not used inside the PatchesThe 0.7.2 release of the WorkaroundsNone. Fixed in
0.7.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-34353
GHSA-9ggc-845v-gcgv
May 13, 2024
matrix-sdk-crypto contains a log exposure of private key of the server-side key backup
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
High
None
None
IntroductionIn Matrix, the server-side key backup stores encrypted copies of Matrix message keys. This facilitates key sharing between a user's devices and provides a redundant copy in case all devices are lost. The key backup uses asymmetric cryptography, with each server-side key backup assigned a unique public-private key pair. ImpactDue to a logic bug introduced in https://github.com/matrix-org/matrix-rust-sdk/pull/2961/commits/71136e44c03c79f80d6d1a2446673bc4d53a2067, the matrix-sdk-crypto crate version 0.7.0 will sometimes log the private part of the backup key pair to Rust debug logs (using the PatchesThis issue has been resolved in matrix-sdk-crypto version 0.7.1. WorkaroundsNone. ReferencesFor more informationIf you have any questions or comments about this advisory, please email us at security at matrix.org. Affected versions
0.7.0
Fixed in
0.7.1
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.7.0
unknown
Dependencies (43)
+ 35 more |
|
0.6.0
unknown
2 CVEs
CVE-2024-52813
GHSA-r5vf-wf4h-82gg
RUSTSEC-2024-0434
Jan 07, 2025
matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactVersions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK to overlook such changes. Patchesmatrix-sdk-crypto 0.8.0 adds a new References
Fixed in
0.8.0
References Updated Jan 22, 2025 · Source: OSV.dev
CVE-2024-40648
GHSA-4qg4-cvh2-crgg
RUSTSEC-2024-0356
Jul 18, 2024
matrix-sdk-crypto's `UserIdentity::is_verified` not checking verification status of own user identity while performing the check
Medium
Network
Low
None
None
The ImpactIf the method is used to decide whether to perform sensitive operations towards a user identity, a malicious homeserver could manipulate the outcome in order to make the identity appear trusted. This is not a typical usage of the method, which lowers the impact. The method itself is not used inside the PatchesThe 0.7.2 release of the WorkaroundsNone. Fixed in
0.7.2
References
Updated Sep 10, 2026 · Source: OSV.dev |
0.6.0
unknown
Dependencies (33)
+ 25 more |
|
0.5.0
unknown
3 CVEs
CVE-2024-52813
GHSA-r5vf-wf4h-82gg
RUSTSEC-2024-0434
Jan 07, 2025
matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactVersions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK to overlook such changes. Patchesmatrix-sdk-crypto 0.8.0 adds a new References
Fixed in
0.8.0
References Updated Jan 22, 2025 · Source: OSV.dev
CVE-2024-40648
GHSA-4qg4-cvh2-crgg
RUSTSEC-2024-0356
Jul 18, 2024
matrix-sdk-crypto's `UserIdentity::is_verified` not checking verification status of own user identity while performing the check
Medium
Network
Low
None
None
The ImpactIf the method is used to decide whether to perform sensitive operations towards a user identity, a malicious homeserver could manipulate the outcome in order to make the identity appear trusted. This is not a typical usage of the method, which lowers the impact. The method itself is not used inside the PatchesThe 0.7.2 release of the WorkaroundsNone. Fixed in
0.7.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39252
GHSA-vp68-2wrm-69qm
RUSTSEC-2022-0085
Sep 30, 2022
matrix-sdk-crypto contains potential impersonation via room key forward responses
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactWhen matrix-rust-sdk before 0.6 requests a room key from our devices, it correctly accepts key forwards only if they are a response to a previous request. However, it doesn't check that the device that responded matches the device the key was requested from. This allows a malicious homeserver to insert room keys of questionable validity into the key store in some situations, potentially assisting in an impersonation attack. Note that even if key injection succeeds in this way, all forwarded keys have the For more informationIf you have any questions or comments about this advisory, e-mail us at security@matrix.org. Fixed in
0.6.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.5.0
unknown
Dependencies (26)
+ 18 more |
|
0.4.1
unknown
3 CVEs
CVE-2024-52813
GHSA-r5vf-wf4h-82gg
RUSTSEC-2024-0434
Jan 07, 2025
matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactVersions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK to overlook such changes. Patchesmatrix-sdk-crypto 0.8.0 adds a new References
Fixed in
0.8.0
References Updated Jan 22, 2025 · Source: OSV.dev
CVE-2024-40648
GHSA-4qg4-cvh2-crgg
RUSTSEC-2024-0356
Jul 18, 2024
matrix-sdk-crypto's `UserIdentity::is_verified` not checking verification status of own user identity while performing the check
Medium
Network
Low
None
None
The ImpactIf the method is used to decide whether to perform sensitive operations towards a user identity, a malicious homeserver could manipulate the outcome in order to make the identity appear trusted. This is not a typical usage of the method, which lowers the impact. The method itself is not used inside the PatchesThe 0.7.2 release of the WorkaroundsNone. Fixed in
0.7.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39252
GHSA-vp68-2wrm-69qm
RUSTSEC-2022-0085
Sep 30, 2022
matrix-sdk-crypto contains potential impersonation via room key forward responses
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactWhen matrix-rust-sdk before 0.6 requests a room key from our devices, it correctly accepts key forwards only if they are a response to a previous request. However, it doesn't check that the device that responded matches the device the key was requested from. This allows a malicious homeserver to insert room keys of questionable validity into the key store in some situations, potentially assisting in an impersonation attack. Note that even if key injection succeeds in this way, all forwarded keys have the For more informationIf you have any questions or comments about this advisory, e-mail us at security@matrix.org. Fixed in
0.6.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.4.1
unknown
Dependencies (31)
+ 23 more |
|
0.4.0
unknown
3 CVEs
CVE-2024-52813
GHSA-r5vf-wf4h-82gg
RUSTSEC-2024-0434
Jan 07, 2025
matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactVersions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK to overlook such changes. Patchesmatrix-sdk-crypto 0.8.0 adds a new References
Fixed in
0.8.0
References Updated Jan 22, 2025 · Source: OSV.dev
CVE-2024-40648
GHSA-4qg4-cvh2-crgg
RUSTSEC-2024-0356
Jul 18, 2024
matrix-sdk-crypto's `UserIdentity::is_verified` not checking verification status of own user identity while performing the check
Medium
Network
Low
None
None
The ImpactIf the method is used to decide whether to perform sensitive operations towards a user identity, a malicious homeserver could manipulate the outcome in order to make the identity appear trusted. This is not a typical usage of the method, which lowers the impact. The method itself is not used inside the PatchesThe 0.7.2 release of the WorkaroundsNone. Fixed in
0.7.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39252
GHSA-vp68-2wrm-69qm
RUSTSEC-2022-0085
Sep 30, 2022
matrix-sdk-crypto contains potential impersonation via room key forward responses
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactWhen matrix-rust-sdk before 0.6 requests a room key from our devices, it correctly accepts key forwards only if they are a response to a previous request. However, it doesn't check that the device that responded matches the device the key was requested from. This allows a malicious homeserver to insert room keys of questionable validity into the key store in some situations, potentially assisting in an impersonation attack. Note that even if key injection succeeds in this way, all forwarded keys have the For more informationIf you have any questions or comments about this advisory, e-mail us at security@matrix.org. Fixed in
0.6.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.4.0
unknown
Dependencies (31)
+ 23 more |
|
0.3.0
unknown
3 CVEs
CVE-2024-52813
GHSA-r5vf-wf4h-82gg
RUSTSEC-2024-0434
Jan 07, 2025
matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactVersions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK to overlook such changes. Patchesmatrix-sdk-crypto 0.8.0 adds a new References
Fixed in
0.8.0
References Updated Jan 22, 2025 · Source: OSV.dev
CVE-2024-40648
GHSA-4qg4-cvh2-crgg
RUSTSEC-2024-0356
Jul 18, 2024
matrix-sdk-crypto's `UserIdentity::is_verified` not checking verification status of own user identity while performing the check
Medium
Network
Low
None
None
The ImpactIf the method is used to decide whether to perform sensitive operations towards a user identity, a malicious homeserver could manipulate the outcome in order to make the identity appear trusted. This is not a typical usage of the method, which lowers the impact. The method itself is not used inside the PatchesThe 0.7.2 release of the WorkaroundsNone. Fixed in
0.7.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39252
GHSA-vp68-2wrm-69qm
RUSTSEC-2022-0085
Sep 30, 2022
matrix-sdk-crypto contains potential impersonation via room key forward responses
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactWhen matrix-rust-sdk before 0.6 requests a room key from our devices, it correctly accepts key forwards only if they are a response to a previous request. However, it doesn't check that the device that responded matches the device the key was requested from. This allows a malicious homeserver to insert room keys of questionable validity into the key store in some situations, potentially assisting in an impersonation attack. Note that even if key injection succeeds in this way, all forwarded keys have the For more informationIf you have any questions or comments about this advisory, e-mail us at security@matrix.org. Fixed in
0.6.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.3.0
unknown
Dependencies (30)
+ 22 more |
|
0.2.0
unknown
3 CVEs
CVE-2024-52813
GHSA-r5vf-wf4h-82gg
RUSTSEC-2024-0434
Jan 07, 2025
matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactVersions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK to overlook such changes. Patchesmatrix-sdk-crypto 0.8.0 adds a new References
Fixed in
0.8.0
References Updated Jan 22, 2025 · Source: OSV.dev
CVE-2024-40648
GHSA-4qg4-cvh2-crgg
RUSTSEC-2024-0356
Jul 18, 2024
matrix-sdk-crypto's `UserIdentity::is_verified` not checking verification status of own user identity while performing the check
Medium
Network
Low
None
None
The ImpactIf the method is used to decide whether to perform sensitive operations towards a user identity, a malicious homeserver could manipulate the outcome in order to make the identity appear trusted. This is not a typical usage of the method, which lowers the impact. The method itself is not used inside the PatchesThe 0.7.2 release of the WorkaroundsNone. Fixed in
0.7.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39252
GHSA-vp68-2wrm-69qm
RUSTSEC-2022-0085
Sep 30, 2022
matrix-sdk-crypto contains potential impersonation via room key forward responses
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactWhen matrix-rust-sdk before 0.6 requests a room key from our devices, it correctly accepts key forwards only if they are a response to a previous request. However, it doesn't check that the device that responded matches the device the key was requested from. This allows a malicious homeserver to insert room keys of questionable validity into the key store in some situations, potentially assisting in an impersonation attack. Note that even if key injection succeeds in this way, all forwarded keys have the For more informationIf you have any questions or comments about this advisory, e-mail us at security@matrix.org. Fixed in
0.6.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.2.0
unknown
Dependencies (27)
+ 19 more |
|
0.1.0
unknown
3 CVEs
CVE-2024-52813
GHSA-r5vf-wf4h-82gg
RUSTSEC-2024-0434
Jan 07, 2025
matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactVersions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK to overlook such changes. Patchesmatrix-sdk-crypto 0.8.0 adds a new References
Fixed in
0.8.0
References Updated Jan 22, 2025 · Source: OSV.dev
CVE-2024-40648
GHSA-4qg4-cvh2-crgg
RUSTSEC-2024-0356
Jul 18, 2024
matrix-sdk-crypto's `UserIdentity::is_verified` not checking verification status of own user identity while performing the check
Medium
Network
Low
None
None
The ImpactIf the method is used to decide whether to perform sensitive operations towards a user identity, a malicious homeserver could manipulate the outcome in order to make the identity appear trusted. This is not a typical usage of the method, which lowers the impact. The method itself is not used inside the PatchesThe 0.7.2 release of the WorkaroundsNone. Fixed in
0.7.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-39252
GHSA-vp68-2wrm-69qm
RUSTSEC-2022-0085
Sep 30, 2022
matrix-sdk-crypto contains potential impersonation via room key forward responses
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
ImpactWhen matrix-rust-sdk before 0.6 requests a room key from our devices, it correctly accepts key forwards only if they are a response to a previous request. However, it doesn't check that the device that responded matches the device the key was requested from. This allows a malicious homeserver to insert room keys of questionable validity into the key store in some situations, potentially assisting in an impersonation attack. Note that even if key injection succeeds in this way, all forwarded keys have the For more informationIf you have any questions or comments about this advisory, e-mail us at security@matrix.org. Fixed in
0.6.0
References
Updated Nov 08, 2023 · Source: OSV.dev |
0.1.0
unknown
Dependencies (19)
+ 11 more |