GHSA-wchh-9x6h-7f6p

Suggest an improvement
Source
https://github.com/advisories/GHSA-wchh-9x6h-7f6p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-wchh-9x6h-7f6p/GHSA-wchh-9x6h-7f6p.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wchh-9x6h-7f6p
Published
2026-07-29T16:11:45Z
Modified
2026-07-29T16:15:29Z
Summary
olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
Details

Problem

Multiple vulnerabilities were disclosed in 2024 affecting libolm (Olm): AES timing / side‑channel, Ed25519 signature malleability, and timing leaks in base64 decoding; several CVEs were assigned. Patches and mitigations were published; maintainers recommend upgrading to fixed versions. In addition, a 2022 “Olm/Megolm protocol confusion” advisory affecting some SDKs was critical and required client-side fixes. Use patched versions of libolm and up-to-date Matrix SDKs; avoid unpatched clients/servers.

Olm is a dependency of matrix-commander (Python version, not Rust version).

WARNING:

Due to cryptographic olm dependency deprecation, this program is cryptographically unsafe to use until https://github.com/matrix-nio/matrix-nio/pull/555 is merged. Good news: https://github.com/8go/matrix-commander-rs is a Rust alternative not having this issue.

References

Workarounds

Severity:

Medium

CVE-2022-39255 — MEDIUM (NVD/MITRE lists CVSS base score 5.x — treated as Medium).

CVE-2024-45193 — MEDIUM (NVD shows CVSS 3.1 base score ~4.3 — Medium)

Database specific
{
    "cwe_ids": [
        "CWE-1395"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-07-29T16:11:45Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

PyPI / matrix-commander

Package

Name
matrix-commander
View open source insights on deps.dev
Purl
pkg:pypi/matrix-commander

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
8.0.6

Affected versions

2.*
2.16.0
2.17.0
2.18.0
2.19.0
2.20.0
2.21.0
2.23.0
2.24.0
2.27.0
2.28.0
2.29.0
2.30.0
2.31.0
2.32.0
2.34.0
2.34.1
2.35.0
2.36.0
2.37.0
2.38.0
3.*
3.0.0
3.1.0
3.2.0
3.3.0
3.4.0
3.5.0
3.5.19
3.5.24
3.5.25
3.5.26
3.5.27
4.*
4.0.0
5.*
5.0.0
5.1.0
5.2.0
6.*
6.0.0
6.0.1
6.0.2
7.*
7.0.0
7.1.0
7.2.0
7.3.0
7.3.1
7.4.0
7.5.0
7.6.0
7.6.1
7.6.2
7.6.3
7.7.0
7.7.1
8.*
8.0.0
8.0.3
8.0.4
8.0.5
8.0.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-wchh-9x6h-7f6p/GHSA-wchh-9x6h-7f6p.json"