Package impact
crates.io / matrix-sdk-crypto
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-45056 | unknown | — | — | 10h ago | Sender-binding gaps in to-device messages | |||
| CVE-2025-48937 | unknown | — | — | 1y ago | matrix-sdk-crypto vulnerable to encrypted event sender spoofing by homeserver administrator | |||
| CVE-2024-40648 | unknown | — | — | 2y ago | `UserIdentity::is_verified` not checking verification status of own user identity while performing the check | |||
| CVE-2024-34353 | unknown | — | — | 2y ago | matrix-sdk-crypto contains a log exposure of private key of the server-side key backup | |||
| CVE-2024-52813 | unknown | — | — | 2y ago | Missing facility to signal rotation of a verified cryptographic identity | |||
| CVE-2022-39252 | unknown | — | — | 4y ago | matrix-sdk Impersonation of room keys |