Denial-of-Service Vulnerability in Matrix SDK Base Component
CVE-2025-66622
1.3LOW
What is CVE-2025-66622?
The matrix-sdk-base component, which serves as a foundation to build Matrix client libraries, has a vulnerability present in versions up to 0.14.1. This flaw arises from a serialization issue that mismanages responses with custom m.room.join_rules, enabling exploitation for denial-of-service conditions. Specifically, when a user is invited to a room containing non-standard join rules, the synchronization process stutters, leading to a stall that obstructs processing across all rooms. This issue has been rectified in version 0.16.0, ensuring that the library can correctly manage custom join rules and maintain operational integrity.
Affected Version(s)
matrix-rust-sdk < 0.16.0
