CVE-2026-45056: CWE-290: Authentication Bypass by Spoofing in matrix-org matrix-rust-sdk
matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the user ID when decrypting an Olm-encrypted event containing the `sender_device_keys` property. This could be exploited to forge an encrypted to-device event, but only if the attacker colludes with the homeserver operator. This issue is fixed in matrix-sdk-crypto 0.17.0. There are no known workarounds for the issue.
AI Analysis
Technical Summary
The matrix-sdk-crypto crate, used for end-to-end encryption in Matrix clients, lacked a user ID verification step when decrypting Olm-encrypted events with the sender_device_keys property in versions >=0.12.0 and <0.16.1. This flaw could be exploited to forge encrypted to-device events, but only if the attacker collaborates with the homeserver operator. The vulnerability is addressed in version 0.17.0 of matrix-sdk-crypto.
Potential Impact
An attacker who colludes with the homeserver operator can forge encrypted to-device events, potentially bypassing authentication checks. This could undermine the integrity of encrypted communications in affected Matrix clients. There are no known exploits in the wild.
Mitigation Recommendations
Upgrade matrix-sdk-crypto to version 0.17.0 or later, where the vulnerability is fixed. No other workarounds are known.
CVE-2026-45056: CWE-290: Authentication Bypass by Spoofing in matrix-org matrix-rust-sdk
Description
matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the user ID when decrypting an Olm-encrypted event containing the `sender_device_keys` property. This could be exploited to forge an encrypted to-device event, but only if the attacker colludes with the homeserver operator. This issue is fixed in matrix-sdk-crypto 0.17.0. There are no known workarounds for the issue.
CVSS v4.0
Score 6.9medium
Affected software
matrix-org
matrix-rust-sdk
pkg:cargo/matrix-org/matrix-sdk-cryptoRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The matrix-sdk-crypto crate, used for end-to-end encryption in Matrix clients, lacked a user ID verification step when decrypting Olm-encrypted events with the sender_device_keys property in versions >=0.12.0 and <0.16.1. This flaw could be exploited to forge encrypted to-device events, but only if the attacker collaborates with the homeserver operator. The vulnerability is addressed in version 0.17.0 of matrix-sdk-crypto.
Potential Impact
An attacker who colludes with the homeserver operator can forge encrypted to-device events, potentially bypassing authentication checks. This could undermine the integrity of encrypted communications in affected Matrix clients. There are no known exploits in the wild.
Mitigation Recommendations
Upgrade matrix-sdk-crypto to version 0.17.0 or later, where the vulnerability is fixed. No other workarounds are known.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-08T18:07:27.342Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa4737691cc7f3848ae20c6
Added to database: 09/11/2026, 21:32:38 UTC
Last enriched: 09/11/2026, 21:47:38 UTC
Last updated: 09/11/2026, 22:23:23 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.