CVE-2025-66622
EUVD-2025-20182709.12.2025, 16:18
matrix-sdk-base is the base component to build a Matrix client library. Versions 0.14.1 and prior are unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. This is fixed in version 0.16.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| matrix | matrix-rust-sdk | 𝑥 < 0.16.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration