CVE-2026-45056

Source
https://cve.org/CVERecord?id=CVE-2026-45056
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45056.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45056
Aliases
Published
2026-09-11T21:13:56Z
Modified
2026-09-12T11:46:09Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution
Details

matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the user ID when decrypting an Olm-encrypted event containing the sender_device_keys property. This could be exploited to forge an encrypted to-device event, but only if the attacker colludes with the homeserver operator. This issue is fixed in matrix-sdk-crypto 0.17.0. There are no known workarounds for the issue.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-290"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45056.json"
}
References

Affected packages

Git / github.com/matrix-org/matrix-rust-sdk

Affected ranges

Type
GIT
Repo
https://github.com/matrix-org/matrix-rust-sdk
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.12.0"
        },
        {
            "fixed": "0.16.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

matrix-sdk-0.*
matrix-sdk-0.12.0
matrix-sdk-0.13.0
matrix-sdk-0.16.0
matrix-sdk-base-0.*
matrix-sdk-base-0.12.0
matrix-sdk-base-0.13.0
matrix-sdk-base-0.16.0
matrix-sdk-common-0.*
matrix-sdk-common-0.12.0
matrix-sdk-common-0.13.0
matrix-sdk-common-0.16.0
matrix-sdk-crypto-0.*
matrix-sdk-crypto-0.12.0
matrix-sdk-crypto-0.13.0
matrix-sdk-crypto-0.16.0
matrix-sdk-ffi-0.*
matrix-sdk-ffi-0.12.0
matrix-sdk-ffi-0.13.0
matrix-sdk-ffi-0.16.0
Other
matrix-sdk-ffi/20250618
matrix-sdk-ffi/20250701
matrix-sdk-ffi/20250702
matrix-sdk-ffi/20250715
matrix-sdk-ffi/20250728
matrix-sdk-ffi/20250826
matrix-sdk-ffi/20250909
matrix-sdk-ffi/20251007
matrix-sdk-ffi/20251104
matrix-sdk-ffi/20251118
matrix-sdk-ffi/20251202
sdk-ffi/20250923
matrix-sdk-indexeddb-0.*
matrix-sdk-indexeddb-0.12.0
matrix-sdk-indexeddb-0.13.0
matrix-sdk-indexeddb-0.16.0
matrix-sdk-qrcode-0.*
matrix-sdk-qrcode-0.12.0
matrix-sdk-qrcode-0.13.0
matrix-sdk-qrcode-0.16.0
matrix-sdk-search-0.*
matrix-sdk-search-0.16.0
matrix-sdk-sqlite-0.*
matrix-sdk-sqlite-0.12.0
matrix-sdk-sqlite-0.13.0
matrix-sdk-sqlite-0.16.0
matrix-sdk-store-encryption-0.*
matrix-sdk-store-encryption-0.12.0
matrix-sdk-store-encryption-0.13.0
matrix-sdk-store-encryption-0.16.0
matrix-sdk-test-0.*
matrix-sdk-test-0.12.0
matrix-sdk-test-0.13.0
matrix-sdk-test-0.16.0
matrix-sdk-test-macros-0.*
matrix-sdk-test-macros-0.12.0
matrix-sdk-test-macros-0.13.0
matrix-sdk-test-macros-0.16.0
matrix-sdk-test-utils-0.*
matrix-sdk-test-utils-0.16.0
matrix-sdk-ui-0.*
matrix-sdk-ui-0.12.0
matrix-sdk-ui-0.13.0
matrix-sdk-ui-0.16.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45056.json"