Vulnerability RUSTSEC-2026-0159

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
4 months ago
June 03, 2026 at 12:00 PM UTC
Sender-binding gaps in to-device messages
0.12.0 - 0.16.0
0.12.0 - 0.16.0

Summary

Sender-binding gaps in to-device messages

Details

The matrix-sdk-crypto crate before 0.16.1 is missing a check for the sender's user ID when decrypting an Olm-encrypted to-device message containing the sender_device_keys property.

This could be exploited to spoof the sender of an encrypted to-device message, but only if the attacker colludes with (or is) the homeserver operator.

Impacted packages

Timeline

Published
4 months ago
June 03, 2026 at 12:00 PM UTC
Fixed (0.16.1)
4 months ago
May 08, 2026 at 02:03 PM UTC
Last Modified
3 months ago
June 04, 2026 at 12:15 PM UTC