VYPR

crates.io package

matrix-sdk-ui

pkg:cargo/matrix-sdk-ui

Vulnerabilities (1)

  • CVE-2026-45057Jun 4, 2026
    affected < 0.16.1fixed 0.16.1

    ### Impact The message edit validation logic in the `matrix-sdk-ui` crate before 0.16.1 is missing a check: when replacing an encrypted event, the replacement event itself is not required to be encrypted. This enables a malicious homeserver administrator (or an actor with equiva