VYPR

matrix-sdk-crypto

by Matrix Org

Source repositories

CVEs (1)

  • CVE-2026-45056Jun 4, 2026
    risk 0.00cvss epss

    ### Impact The `matrix-sdk-crypto` crate before 0.16.1 is missing a check for the sender's user ID when decrypting an Olm-encrypted to-device message containing the `sender_device_keys` property. This could be exploited to spoof the sender of an encrypted to-device message,…