Vulnerability GHSA-wfq4-36m3-9g42

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
3 months ago
June 04, 2026 at 02:47 PM UTC
Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution
0.12.0 - 0.16.0
0.12.0 - 0.16.0

Summary

Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution

Details

Impact

The matrix-sdk-crypto crate before 0.16.1 is missing a check for the sender's user ID when decrypting an Olm-encrypted to-device message containing the sender_device_keys property.

This could be exploited to spoof the sender of an encrypted to-device message, but only if the attacker colludes with (or is) the homeserver operator.

Patches

This issue is fixed in matrix-sdk-crypto 0.16.1.

Workarounds

There are no known workarounds for the issue.

References

This issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/6553.

For more information

If you have any questions or comments about this advisory, please email us at security at matrix.org.

Impacted packages

Timeline

Published
3 months ago
June 04, 2026 at 02:47 PM UTC
Fixed (0.16.1)
4 months ago
May 08, 2026 at 02:03 PM UTC
Last Modified
3 months ago
June 04, 2026 at 03:00 PM UTC