{"id":"CVE-2025-66622","title":"matrix-sdk-base is the base component to build a Matrix client library","summary":"matrix-sdk-base is the base component to build a Matrix client library. Versions 0.14.1 and prior are unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a de…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-755"],"vendor":"matrix","product":"matrix-rust-sdk","affected":["matrix-rust-sdk < 0.16.0"],"patched":["matrix-rust-sdk 0.16.0"],"published":"2025-12-09","updated":"2026-10-07","sourceUpdated":"2026-10-07T20:10:01.970","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-66622","references":[{"url":"https://github.com/matrix-org/matrix-rust-sdk/commit/4ea0418abefab2aa93f8851a4d39c723e703e6b0","label":"security-advisories@github.com"},{"url":"https://github.com/matrix-org/matrix-rust-sdk/pull/5924","label":"security-advisories@github.com"},{"url":"https://github.com/matrix-org/matrix-rust-sdk/security/advisories/GHSA-jj6p-3m75-g2p3","label":"security-advisories@github.com"},{"url":"https://rustsec.org/advisories/RUSTSEC-2025-0135.html","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00413,"epssPercentile":0.33413,"ingestedAt":"2026-10-07T20:46:46.829Z","slug":"CVE-2025-66622","body":"## Overview\n\nmatrix-sdk-base is the base component to build a Matrix client library. Versions 0.14.1 and prior are unable to handle responses that include custom m.room.join_rules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. This is fixed in version 0.16.0.\n\n## Affected\n\n- `matrix-rust-sdk < 0.16.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `matrix-rust-sdk 0.16.0`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}