Vulnerabilities

Last updated 50 minutes ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
matrix-sdk-crypto Sending custom to-device messages may panics Unknown 2 days ago 8 hours ago
matrix-sdk-crypto matrix-sdk-crypto's `UserIdentity::is_verified` not checking verification status of own user identity while performing the check Medium Risk 4.8 2 years ago 22 days ago
matrix-sdk-crypto matrix-sdk-crypto contains a log exposure of private key of the server-side key backup Medium Risk 5.5 2 years ago 22 days ago
matrix-sdk-crypto Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution Medium Risk 6.0 3 months ago 3 months ago
matrix-sdk-crypto Sender-binding gaps in to-device messages Unknown 4 months ago 3 months ago
matrix-sdk-crypto matrix-sdk-crypto vulnerable to sender of encrypted events being spoofed by homeserver administrator Medium Risk 4.9 1 year ago 1 year ago
matrix-sdk-crypto matrix-sdk-crypto vulnerable to encrypted event sender spoofing by homeserver administrator Medium Risk 4.9 1 year ago 1 year ago
matrix-sdk-crypto matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity Medium Risk 4.3 1 year ago 1 year ago
matrix-sdk-crypto Missing facility to signal rotation of a verified cryptographic identity Unknown 2 years ago 1 year ago
matrix-sdk-crypto `UserIdentity::is_verified` not checking verification status of own user identity while performing the check Unknown 2 years ago 2 years ago
matrix-sdk-crypto matrix-sdk-crypto contains potential impersonation via room key forward responses Medium Risk 6.5 4 years ago 2 years ago
matrix-sdk-crypto matrix-sdk Impersonation of room keys High Risk 7.5 4 years ago 2 years ago