PT-2022-24846 · Unknown · Matrix-Nio

·

CVE-2022-39254

·

Published

2022-09-29

·

Updated

2026-07-07

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions matrix-nio versions prior to 0.20
Description The issue arises when a user requests a room key from their devices. The software remembers the request but fails to check the origin of the forwarded room key, allowing homeservers to potentially insert room keys of questionable validity and mount an impersonation attack.
Recommendations For versions prior to 0.20, update to version 0.20 to resolve the issue. As a temporary workaround, consider restricting the acceptance of forwarded room keys to only those that are responses to previous requests and match the device the key was requested from.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-39254
GHSA-W4PR-4VJG-HFFH
PYSEC-2026-842

Affected Products

Matrix-Nio