Dependency on Vulnerable Third-Party Component Affecting matrix-nio package, versions [,0.26.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-MATRIXNIO-18507998
  • published2 Aug 2026
  • disclosed29 Jul 2026
  • creditUnknown

Introduced: 29 Jul 2026

New CVE NOT AVAILABLE CWE-1395  (opens in a new tab)

How to fix?

Upgrade matrix-nio to version 0.26.0 or higher.

Overview

matrix-nio is an A Python Matrix client library, designed according to sans I/O principles.

Affected versions of this package are vulnerable to Dependency on Vulnerable Third-Party Component due to the use of a deprecated cryptographic dependency, which introduces multiple cryptographic weaknesses including timing side-channels and signature malleability in the olm process. An attacker can compromise the confidentiality or integrity of encrypted communications by exploiting these cryptographic flaws.

CVSS Base Scores

version 4.0
version 3.1