Vulnerability RUSTSEC-2026-0318

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 days ago
September 29, 2026 at 12:00 PM UTC
Sending custom to-device messages may panics
0.1.0 - 0.18.0
0.1.0 - 0.18.0

Summary

Sending custom to-device messages may panics

Details

Using the IdentityBasedStrategy setting when calling Device::encrypt_event_raw or OlmMachine::encrypt_content_for_devices may cause a panic if the recipient does not have cross-signing keys.

Impacted packages

Timeline

Published
2 days ago
September 29, 2026 at 12:00 PM UTC
Fixed (0.19.0)
15 days ago
September 16, 2026 at 01:02 PM UTC
Last Modified
6 hours ago
October 01, 2026 at 08:30 PM UTC