Junglewise Threat Intelligence

CVE-2026-45056: matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in ve

CVE-2026-45056 · Severity: medium · CVSS 4 · Published 2026-09-11

Technologies: matrix-sdk-crypto (crates.io). Vendors: crates.io.

Executive brief

A security flaw in the Matrix Rust SDK's encryption component could allow a malicious server operator to impersonate other users. By exploiting a missing identity check during message decryption, an attacker could send forged private messages that appear to come from a trusted contact. This undermines the authenticity of communications within the Matrix messaging network.

Technical details

The matrix-sdk-crypto crate fails to validate the sender's user ID when decrypting Olm-encrypted to-device messages that include the sender_device_keys property. This vulnerability, classified as CWE-290 (Authentication Bypass by Spoofing), allows an attacker who controls or colludes with a homeserver operator to forge the origin of encrypted messages. The root cause is located in the decryption logic where the embedded device keys are not properly bound to the expected sender's identity. The issue is resolved in version 0.16.1 by implementing a mandatory check for the user ID in the embedded device keys.

Affected products

  • Matrix matrix-sdk-crypto >= 0.12.0, < 0.16.1

Timeline

  • 2026-05-08: patched: Fix merged in pull request 6553 and released in version 0.16.1
  • 2026-06-03: disclosed: Initial disclosure by dkasak
  • 2026-06-04: advisory: GitHub Advisory GHSA-wfq4-36m3-9g42 published

References

Related threats