<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:18:47 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-243695</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-243695</link>
      <description>EUVD-2026-243695</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-243695</guid>
    </item>
    <item>
      <title>fkie_cve-2025-48937</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-48937</link>
      <description>&lt;p&gt;matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. matrix-sdk-crypto since version 0.8.0 and up to 0.11.0 does not correctly validate the sender of an encrypted event. Accordingly, a malicious homeserver operator can modify events served to clients, making those events appear to the recipient as if they were sent by another user. This vulnerability is fixed in 0.11.1 and 0.12.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. matrix-sdk-crypto since version 0.8.0 and up to 0.11.0 does not correctly validate the sender of an encrypted event. Accordingly, a malicious homeserver operator can modify events served to clients, making those events appear to the recipient as if they were sent by another user. This vulnerability is fixed in 0.11.1 and 0.12.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-48937</guid>
    </item>
    <item>
      <title>GHSA-x958-rvg6-956w — matrix-sdk-crypto vulnerable to sender of encrypted events being spoofed by homeserver administrator</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x958-rvg6-956w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: matrix-sdk-crypto&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;matrix-sdk-crypto since version 0.8.0 up to 0.11.0 does not correctly validate the sender of an encrypted event. Accordingly, a malicious homeserver operator can modify events served to clients, making those events appear to the recipient as if they were sent by another user.&lt;/p&gt;
&lt;p&gt;Although the CVSS score is 4.9 (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N), we consider this a High Severity security issue.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The Matrix specification [requires](https://spec.matrix.org/v1.14/client-server-api/#mmegolmv1aes-sha2) that clients ensure that &amp;#34;the event’s `sender`, `room_id`, and the recorded `session_id` match a trusted session&amp;#34;. The vulnerable matrix-sdk-crypto versions check that the `room_id` matches that of the session denoted by `session_id`, but do not check the `sender`.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The issue is resolved by [13c1d20](https://github.com/matrix-org/matrix-rust-sdk/commit/13c1d2048286bbabf5e7bc6b015aafee98f04d55), included in versions 0.11.1 and 0.12.0 of matrix-sdk-crypto.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Since a successful attack requires administrator access to the homeserver, users who trust the administrators of their local homeserver are not affected.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;* https://spec.matrix.org/v1.14/client-server-api/#mmegolmv1aes-sha2&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: matrix-sdk-crypto&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;matrix-sdk-crypto since version 0.8.0 up to 0.11.0 does not correctly validate the sender of an encrypted event. Accordingly, a malicious homeserver operator can modify events served to clients, making those events appear to the recipient as if they were sent by another user.&lt;/p&gt;
&lt;p&gt;Although the CVSS score is 4.9 (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N), we consider this a High Severity security issue.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The Matrix specification [requires](https://spec.matrix.org/v1.14/client-server-api/#mmegolmv1aes-sha2) that clients ensure that &amp;#34;the event’s `sender`, `room_id`, and the recorded `session_id` match a trusted session&amp;#34;. The vulnerable matrix-sdk-crypto versions check that the `room_id` matches that of the session denoted by `session_id`, but do not check the `sender`.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;The issue is resolved by [13c1d20](https://github.com/matrix-org/matrix-rust-sdk/commit/13c1d2048286bbabf5e7bc6b015aafee98f04d55), included in versions 0.11.1 and 0.12.0 of matrix-sdk-crypto.&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Since a successful attack requires administrator access to the homeserver, users who trust the administrators of their local homeserver are not affected.&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;* https://spec.matrix.org/v1.14/client-server-api/#mmegolmv1aes-sha2&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x958-rvg6-956w</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15218-1 — fractal-11.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15218-1</link>
      <description>&lt;p&gt;fractal-11.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;fractal-11.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15218-1</guid>
    </item>
    <item>
      <title>RUSTSEC-2025-0041 — matrix-sdk-crypto vulnerable to encrypted event sender spoofing by homeserver administrator</title>
      <link>https://cve.radiocsirt.org/vuln/rustsec-2025-0041</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: matrix-sdk-crypto&lt;/p&gt;
&lt;p&gt;matrix-sdk-crypto versions 0.8.0 up to and including 0.11.0 does not correctly validate
the sender of an encrypted event. Accordingly, a malicious homeserver operator
can modify events served to clients, making those events appear to the recipient
as if they were sent by another user.&lt;/p&gt;
&lt;p&gt;Although the CVSS score is 4.9 (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N), we
consider this a High severity security issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; crates.io: matrix-sdk-crypto&lt;/p&gt;
&lt;p&gt;matrix-sdk-crypto versions 0.8.0 up to and including 0.11.0 does not correctly validate
the sender of an encrypted event. Accordingly, a malicious homeserver operator
can modify events served to clients, making those events appear to the recipient
as if they were sent by another user.&lt;/p&gt;
&lt;p&gt;Although the CVSS score is 4.9 (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N), we
consider this a High severity security issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rustsec-2025-0041</guid>
    </item>
  </channel>
</rss>
