Vulnerability RUSTSEC-2026-0318
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 days ago
September 29, 2026 at 12:00 PM UTC
Sending custom to-device messages may panics
0.1.0 - 0.18.0
0.1.0 - 0.18.0
Summary
Sending custom to-device messages may panics
Details
Using the IdentityBasedStrategy setting when calling Device::encrypt_event_raw or OlmMachine::encrypt_content_for_devices may cause a panic if the recipient does not have cross-signing keys.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
3 months ago
Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution
0.12.0 - 0.16.0 GHSA-wfq4-36m3-9g42
0.12.0 - 0.16.0 GHSA-wfq4-36m3-9g42
Unknown
4 months ago
Sender-binding gaps in to-device messages
0.12.0 - 0.16.0 RUSTSEC-2026-0159
0.12.0 - 0.16.0 RUSTSEC-2026-0159
Medium Risk
1 year ago
matrix-sdk-crypto vulnerable to encrypted event sender spoofing by homeserver administrator
0.8.0 - 0.11.0 RUSTSEC-2025-0041
0.8.0 - 0.11.0 RUSTSEC-2025-0041
Medium Risk
1 year ago
matrix-sdk-crypto vulnerable to sender of encrypted events being spoofed by homeserver administrator
0.8.0 - 0.11.0 GHSA-x958-rvg6-956w
0.8.0 - 0.11.0 GHSA-x958-rvg6-956w
Medium Risk
1 year ago
matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity
0.1.0 - 0.7.2 GHSA-r5vf-wf4h-82gg
0.1.0 - 0.7.2 GHSA-r5vf-wf4h-82gg
Impacted packages
Timeline
Published
2 days ago
September 29, 2026 at 12:00 PM UTC
Fixed (0.19.0)
15 days ago
September 16, 2026 at 01:02 PM UTC
Last Modified
6 hours ago
October 01, 2026 at 08:30 PM UTC