{"id":"PYSEC-2026-842","summary":"When matrix-nio receives forwarded room keys, the receiver doesn't check if it requested the key from the forwarder","details":"When matrix-nio before 0.20 requests a room key from our devices, it correctly accepts key forwards only if they are a response to a previous request. However, it doesn't check that the device that responded matches the device the key was requested from.\n\nThis allows a malicious homeserver to insert room keys of questionable validity into the key store in some situations, potentially assisting in an impersonation attack.\n\n### For more information\nIf you have any questions or comments about this advisory, e-mail us at [poljar@termina.org.uk](mailto:poljar@termina.org.uk).","aliases":["CVE-2022-39254","GHSA-w4pr-4vjg-hffh"],"modified":"2026-07-07T11:46:05.855618817Z","published":"2026-07-07T10:17:22.451432Z","references":[{"type":"WEB","url":"https://github.com/poljar/matrix-nio/security/advisories/GHSA-w4pr-4vjg-hffh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-39254"},{"type":"WEB","url":"https://github.com/poljar/matrix-nio/commit/b1cbf234a831daa160673defd596e6450e9c29f0"},{"type":"PACKAGE","url":"https://github.com/poljar/matrix-nio"},{"type":"PACKAGE","url":"https://pypi.org/project/matrix-nio"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w4pr-4vjg-hffh"}],"affected":[{"package":{"name":"matrix-nio","ecosystem":"PyPI","purl":"pkg:pypi/matrix-nio"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.20"}]}],"versions":["0.10.0","0.11.0","0.11.1","0.11.2","0.12.0","0.13.0","0.14.0","0.14.1","0.15.0","0.15.1","0.15.2","0.16.0","0.17.0","0.18.0","0.18.1","0.18.2","0.18.3","0.18.4","0.18.5","0.18.6","0.18.7","0.19.0","0.2","0.3","0.4","0.4.1","0.5","0.6","0.7","0.7.1","0.7.2","0.8.0","0.9.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/matrix-nio/PYSEC-2026-842.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N"}]}