Vulnerability RUSTSEC-2025-0041
Medium Risk
MEDIUM RISK
CVSS Score: 4.9
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
1 year ago
June 11, 2025 at 12:00 PM UTC
matrix-sdk-crypto vulnerable to encrypted event sender spoofing by homeserver administrator
0.8.0 - 0.11.0
0.8.0 - 0.11.0
Summary
matrix-sdk-crypto vulnerable to encrypted event sender spoofing by homeserver administrator
Details
matrix-sdk-crypto versions 0.8.0 up to and including 0.11.0 does not correctly validate the sender of an encrypted event. Accordingly, a malicious homeserver operator can modify events served to clients, making those events appear to the recipient as if they were sent by another user.
Although the CVSS score is 4.9 (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N), we consider this a High severity security issue.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
2 days ago
Sending custom to-device messages may panics
0.1.0 - 0.18.0 RUSTSEC-2026-0318
0.1.0 - 0.18.0 RUSTSEC-2026-0318
Medium Risk
3 months ago
Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution
0.12.0 - 0.16.0 GHSA-wfq4-36m3-9g42
0.12.0 - 0.16.0 GHSA-wfq4-36m3-9g42
Unknown
4 months ago
Sender-binding gaps in to-device messages
0.12.0 - 0.16.0 RUSTSEC-2026-0159
0.12.0 - 0.16.0 RUSTSEC-2026-0159
Medium Risk
1 year ago
matrix-sdk-crypto vulnerable to sender of encrypted events being spoofed by homeserver administrator
0.8.0 - 0.11.0 GHSA-x958-rvg6-956w
0.8.0 - 0.11.0 GHSA-x958-rvg6-956w
Medium Risk
1 year ago
matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity
0.1.0 - 0.7.2 GHSA-r5vf-wf4h-82gg
0.1.0 - 0.7.2 GHSA-r5vf-wf4h-82gg
Impacted packages
Timeline
Published
1 year ago
June 11, 2025 at 12:00 PM UTC
Fixed (0.11.1)
1 year ago
June 10, 2025 at 10:41 AM UTC
Last Modified
1 year ago
June 12, 2025 at 09:41 AM UTC