Vulnerability RUSTSEC-2026-0159
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
4 months ago
June 03, 2026 at 12:00 PM UTC
Sender-binding gaps in to-device messages
0.12.0 - 0.16.0
0.12.0 - 0.16.0
Summary
Sender-binding gaps in to-device messages
Details
The matrix-sdk-crypto crate before 0.16.1 is missing a check for the sender's user ID when decrypting an Olm-encrypted to-device message containing the sender_device_keys property.
This could be exploited to spoof the sender of an encrypted to-device message, but only if the attacker colludes with (or is) the homeserver operator.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
2 days ago
Sending custom to-device messages may panics
0.1.0 - 0.18.0 RUSTSEC-2026-0318
0.1.0 - 0.18.0 RUSTSEC-2026-0318
Medium Risk
3 months ago
Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution
0.12.0 - 0.16.0 GHSA-wfq4-36m3-9g42
0.12.0 - 0.16.0 GHSA-wfq4-36m3-9g42
Medium Risk
1 year ago
matrix-sdk-crypto vulnerable to encrypted event sender spoofing by homeserver administrator
0.8.0 - 0.11.0 RUSTSEC-2025-0041
0.8.0 - 0.11.0 RUSTSEC-2025-0041
Medium Risk
1 year ago
matrix-sdk-crypto vulnerable to sender of encrypted events being spoofed by homeserver administrator
0.8.0 - 0.11.0 GHSA-x958-rvg6-956w
0.8.0 - 0.11.0 GHSA-x958-rvg6-956w
Medium Risk
1 year ago
matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity
0.1.0 - 0.7.2 GHSA-r5vf-wf4h-82gg
0.1.0 - 0.7.2 GHSA-r5vf-wf4h-82gg
Impacted packages
Timeline
Published
4 months ago
June 03, 2026 at 12:00 PM UTC
Fixed (0.16.1)
4 months ago
May 08, 2026 at 02:03 PM UTC
Last Modified
3 months ago
June 04, 2026 at 12:15 PM UTC