Denial-of-Service Vulnerability in Matrix SDK Base Component
CVE-2025-66622

1.3LOW

Key Information:

Vendor

Matrix-org

Vendor
CVE Published:
9 December 2025

What is CVE-2025-66622?

The matrix-sdk-base component, which serves as a foundation to build Matrix client libraries, has a vulnerability present in versions up to 0.14.1. This flaw arises from a serialization issue that mismanages responses with custom m.room.join_rules, enabling exploitation for denial-of-service conditions. Specifically, when a user is invited to a room containing non-standard join rules, the synchronization process stutters, leading to a stall that obstructs processing across all rooms. This issue has been rectified in version 0.16.0, ensuring that the library can correctly manage custom join rules and maintain operational integrity.

Affected Version(s)

matrix-rust-sdk < 0.16.0

References

CVSS V4

Score:
1.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.