Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-wfq4-36m3-9g42 | Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution |
Fri, 11 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the user ID when decrypting an Olm-encrypted event containing the `sender_device_keys` property. This could be exploited to forge an encrypted to-device event, but only if the attacker colludes with the homeserver operator. This issue is fixed in matrix-sdk-crypto 0.17.0. There are no known workarounds for the issue. | |
| Title | Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-11T21:13:56.332Z
Reserved: 2026-05-08T18:07:27.342Z
Link: CVE-2026-45056
No data.
Status : Received
Published: 2026-09-11T22:16:37.263
Modified: 2026-09-11T22:16:37.263
Link: CVE-2026-45056
No data.
OpenCVE Enrichment
Updated: 2026-09-12T06:45:10Z
-
CWE-290
Authentication Bypass by Spoofing
Github GHSA