Denial-of-Service Vulnerability in Matrix SDK Base Component
CVE-2025-66622
What is CVE-2025-66622?
The matrix-sdk-base component, which serves as a foundation to build Matrix client libraries, has a vulnerability present in versions up to 0.14.1. This flaw arises from a serialization issue that mismanages responses with custom m.room.join_rules, enabling exploitation for denial-of-service conditions. Specifically, when a user is invited to a room containing non-standard join rules, the synchronization process stutters, leading to a stall that obstructs processing across all rooms. This issue has been rectified in version 0.16.0, ensuring that the library can correctly manage custom join rules and maintain operational integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
matrix-rust-sdk < 0.16.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
