PT-2026-46305 · Unknown · Matrix-Sdk-Crypto

CVE-2026-45056

·

Published

2026-06-03

·

Updated

2026-09-12

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions matrix-sdk-crypto versions prior to 0.16.1
Description The matrix-sdk-crypto crate fails to verify the sender's user ID during the decryption of Olm-encrypted to-device messages that include the sender device keys property. This flaw allows an attacker to spoof the sender of an encrypted to-device message, provided the attacker is the homeserver operator or is colluding with them.
Recommendations Update to version 0.16.1.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45056
GHSA-WFQ4-36M3-9G42
RUSTSEC-2026-0159

Affected Products

Matrix-Sdk-Crypto