Improper Handling of Exceptional Conditions Affecting matrix-sdk-base package, versions <0.16.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (13th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RUST-MATRIXSDKBASE-14236604
  • published10 Dec 2025
  • disclosed8 Dec 2025
  • creditUnknown

Introduced: 8 Dec 2025

NewCVE-2025-66622  (opens in a new tab)
CWE-755  (opens in a new tab)

How to fix?

Upgrade matrix-sdk-base to version 0.16.0 or higher.

Overview

matrix-sdk-base is a This crate implements the base to build a Matrix client library.

Crate Feature Flags The following crate feature flags are available:

encryption: Enables end-to-end encryption support in the library. qrcode: Enables QRcode generation and reading code. testing: Provides facilities and functions for tests, in particular for integration testing store implementations. ATTENTION: do not ever use outside of tests, we do not provide any stability warantees on these, these are merely helpers. If you find you need any function provided here outside of tests, please open a Github Issue and inform us about your use case for us to consider.

Affected versions of this package are vulnerable to Improper Handling of Exceptional Conditions via the processing of sync responses containing custom m.room.join_rules values. An attacker can cause the process to stall, preventing further processing for all rooms, by inviting a user to a room with non-standard join rules.

Workaround

This vulnerability can be mitigated by leaving affected rooms on another client.

CVSS Base Scores

version 4.0
version 3.1