VDB
Sign up
—

RUSTSEC-2026-0159

Sender-binding gaps in to-device messages

Details

The matrix-sdk-crypto crate before 0.16.1 is missing a check for the sender's user ID when decrypting an Olm-encrypted to-device message containing the sender_device_keys property.

This could be exploited to spoof the sender of an encrypted to-device message, but only if the attacker colludes with (or is) the homeserver operator.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/matrix-sdk-crypto
Introduced in: 0.12.0Fixed in: 0.16.1

Upgrade matrix-sdk-crypto to 0.16.1 or newer (ecosystem crates.io).

References