{"id":"CVE-2026-45056","summary":"Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution","details":"matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the user ID when decrypting an Olm-encrypted event containing the `sender_device_keys` property. This could be exploited to forge an encrypted to-device event, but only if the attacker colludes with the homeserver operator. This issue is fixed in matrix-sdk-crypto 0.17.0. There are no known workarounds for the issue.","aliases":["GHSA-wfq4-36m3-9g42","RUSTSEC-2026-0159"],"modified":"2026-09-12T11:46:09.620436869Z","published":"2026-09-11T21:13:56.332Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-290"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45056.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45056.json"},{"type":"FIX","url":"https://github.com/matrix-org/matrix-rust-sdk/pull/6553"},{"type":"WEB","url":"https://github.com/matrix-org/matrix-rust-sdk/releases/tag/matrix-sdk-0.16.1"},{"type":"ADVISORY","url":"https://github.com/matrix-org/matrix-rust-sdk/security/advisories/GHSA-wfq4-36m3-9g42"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45056"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2026-0159.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/matrix-org/matrix-rust-sdk","events":[{"introduced":"b41efb063e1faa6579a22dd822777d9e2ce5af81"},{"fixed":"ed148665d211ae97d4672437561ddeccf8556f0d"}],"database_specific":{"extracted_events":[{"introduced":"0.12.0"},{"fixed":"0.16.1"}],"source":"AFFECTED_FIELD"}}],"versions":["matrix-sdk-ui-0.16.0","matrix-sdk-test-utils-0.16.0","matrix-sdk-test-macros-0.16.0","matrix-sdk-test-0.16.0","matrix-sdk-store-encryption-0.16.0","matrix-sdk-sqlite-0.16.0","matrix-sdk-search-0.16.0","matrix-sdk-qrcode-0.16.0","matrix-sdk-indexeddb-0.16.0","matrix-sdk-ffi-0.16.0","matrix-sdk-crypto-0.16.0","matrix-sdk-common-0.16.0","matrix-sdk-base-0.16.0","matrix-sdk-0.16.0","matrix-sdk-ffi/20251202","matrix-sdk-ffi/20251118","matrix-sdk-ffi/20251104","matrix-sdk-ffi/20251007","sdk-ffi/20250923","matrix-sdk-ffi/20250909","matrix-sdk-ffi/20250826","matrix-sdk-ffi/20250728","matrix-sdk-ffi/20250715","matrix-sdk-ui-0.13.0","matrix-sdk-test-macros-0.13.0","matrix-sdk-test-0.13.0","matrix-sdk-store-encryption-0.13.0","matrix-sdk-sqlite-0.13.0","matrix-sdk-qrcode-0.13.0","matrix-sdk-indexeddb-0.13.0","matrix-sdk-ffi-0.13.0","matrix-sdk-crypto-0.13.0","matrix-sdk-common-0.13.0","matrix-sdk-base-0.13.0","matrix-sdk-0.13.0","matrix-sdk-ffi/20250702","matrix-sdk-ffi/20250701","matrix-sdk-ffi/20250618","matrix-sdk-ui-0.12.0","matrix-sdk-test-macros-0.12.0","matrix-sdk-test-0.12.0","matrix-sdk-store-encryption-0.12.0","matrix-sdk-sqlite-0.12.0","matrix-sdk-qrcode-0.12.0","matrix-sdk-indexeddb-0.12.0","matrix-sdk-ffi-0.12.0","matrix-sdk-crypto-0.12.0","matrix-sdk-common-0.12.0","matrix-sdk-base-0.12.0","matrix-sdk-0.12.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45056.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}