nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers inserting malicious secrets, which could lead to man-in-the-middle attacks. Users can upgrade to version 0.10.2 to protect against this issue. As a workaround, one may apply the patch manually, avoid doing verifications of one's own devices, and/or avoid pressing the request button in the settings menu.
{
"cwe_ids": [
"CWE-287",
"CWE-295"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/39xxx/CVE-2022-39264.json",
"cna_assigner": "GitHub_M"
}{
"cpe": "cpe:2.3:a:nheko-reborn:nheko:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.10.2"
}
]
}"2026-07-22T02:08:00Z"
[
{
"signature_type": "Function",
"target": {
"file": "src/encryption/Olm.cpp",
"function": "handle_olm_message"
},
"deprecated": false,
"source": "https://github.com/nheko-reborn/nheko/commit/67bee15a389f9b8a9f6c3a340558d1e2319e7199",
"id": "CVE-2022-39264-6b3898ca",
"signature_version": "v1",
"digest": {
"function_hash": "291018063824603245588392495130773345674",
"length": 7519.0
}
},
{
"signature_type": "Line",
"target": {
"file": "src/encryption/Olm.cpp"
},
"deprecated": false,
"source": "https://github.com/nheko-reborn/nheko/commit/67bee15a389f9b8a9f6c3a340558d1e2319e7199",
"id": "CVE-2022-39264-8a2bcadb",
"signature_version": "v1",
"digest": {
"line_hashes": [
"314031684862769409172070955061539386472",
"325831471101201174799088498847537660337",
"236106384856876904004523395367649960814",
"33196057757508825712225508785285125340",
"233655630507688834009188876799267597409",
"87736103775668621437547075837966295630",
"42417660009787073975988348503050134935",
"226258985755098910598673917254019033526",
"323489760941158113430027110861296831556",
"317670211670070139968806350286375219197",
"174777744952662943395953917597160567225",
"115590786419917342779649742899714198937",
"226709516249676092611947230131027552779",
"748517889673438593601034761148503833",
"220793449359304666462845026858049220793",
"75407180318704451699303769443305508093",
"239745834333312723775072348590760139838",
"283335571474437161250499508538557490317",
"318390849187883225212836371263875386024",
"263595265488124108086666708246724967190",
"55561841630203954757669042069586102372",
"316718824892975356328360280134374930613",
"162842085353348870191657802139718184870",
"217025498892928169449923417542215827748",
"91960459332474571870287936021884841493",
"192777002513267840174796733276251478188",
"142279533790919268777041459653185142491",
"44062342022158676327659156186378197412",
"107566429354175646558288660715061805964",
"310020016146251776373356844405382659919",
"321922646630933077107436414231927492400",
"33025121014981907598564265958629787630"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-39264.json"