Description
matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the user ID when decrypting an Olm-encrypted event containing the `sender_device_keys` property. This could be exploited to forge an encrypted to-device event, but only if the attacker colludes with the homeserver operator. This issue is fixed in matrix-sdk-crypto 0.17.0. There are no known workarounds for the issue.
Published: 2026-09-11
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized event attribution
Action: Patch Now
AI Analysis

Impact

matrix-sdk-crypto, a component of the matrix‑org matrix-rust‑sdk project, handles end-to-end encryption for Matrix clients without performing network I/O. Beginning with version 0.12.0 and continuing through 0.16.x, the crate omitted a check for the user identifier when decrypting Olm-encrypted events that include a sender_device_keys field. This missing check is a CWE-290 flaw that allows an attacker who can collude with the homeserver operator to forge an encrypted to-device event that appears to come from a legitimate user. Although the flaw does not directly enable code execution or data exfiltration, it can mislead a client into attributing a message or policy update to an unrelated user, potentially undermining trust and session integrity.

Affected Systems

The affected product is the matrix‑sdk‑crypto component of matrix‑rust‑sdk from matrix‑org. Versions 0.12.0 through 0.16.x are vulnerable. Updates starting with version 0.17.0 include the missing check and are considered safe.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. The EPSS score is less than 1 % and the vulnerability is not listed in that widespread exploitation is unlikely. However, an attacker would need to collude with a homeserver operator to inject or alter the sender_device_keys during decryption, so the threat is concentrated on privileged or internal actors that can manipulate the homeserver environment.

Generated by OpenCVE AI on September 15, 2026 at 19:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade matrix‑sdk‑crypto to version 0.17.0 or newer.
  • Limit administrative access to the homeserver to trusted personnel and implement strict change‑control procedures to prevent unauthorized modification of sender_device_keys.
  • Separate the homeserver network segment from other internal systems to reduce the risk of collusion or compromise.
  • Maintain an up‑to‑date dependency inventory and monitor the project's repository for new advisories that may re‑introduce similar weaknesses.

Generated by OpenCVE AI on September 15, 2026 at 19:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-wfq4-36m3-9g42 Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Matrix-org
Matrix-org matrix-rust-sdk
Vendors & Products Matrix-org
Matrix-org matrix-rust-sdk

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the user ID when decrypting an Olm-encrypted event containing the `sender_device_keys` property. This could be exploited to forge an encrypted to-device event, but only if the attacker colludes with the homeserver operator. This issue is fixed in matrix-sdk-crypto 0.17.0. There are no known workarounds for the issue.
Title Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution
Weaknesses CWE-290
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Matrix-org Matrix-rust-sdk
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:17:31.910Z

Reserved: 2026-05-08T18:07:27.342Z

Link: CVE-2026-45056

cve-icon Vulnrichment

Updated: 2026-09-14T16:14:49.755Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T22:16:37.263

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-45056

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:45:07Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing