{"id":"GHSA-wchh-9x6h-7f6p","title":"olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193","summary":"olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193","severity":"medium","cwe":["CWE-1395"],"vendor":"matrix-commander","product":"matrix-commander","ecosystem":"pip","affected":["matrix-commander <= 8.0.6"],"published":"2026-07-29","updated":"2026-07-29","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-wchh-9x6h-7f6p","references":[{"url":"https://github.com/8go/matrix-commander/security/advisories/GHSA-wchh-9x6h-7f6p"},{"url":"https://github.com/8go/matrix-commander/issues/204#issuecomment-3523986979"},{"url":"https://github.com/matrix-nio/matrix-nio/pull/555"},{"url":"https://github.com/matrix-nio/matrix-nio/commit/71a1c808bc2ae6ea2a6e8effa7c11bd09796c626"},{"url":"https://github.com/advisories/GHSA-wchh-9x6h-7f6p"}],"tags":["ghsa","pip"],"ingestedAt":"2026-07-29T16:48:33.970Z","slug":"GHSA-wchh-9x6h-7f6p","body":"## Overview\n\n### Problem\n\nMultiple vulnerabilities were disclosed in 2024 affecting libolm (Olm): AES timing / side‑channel, Ed25519 signature malleability, and timing leaks in base64 decoding; several CVEs were assigned. Patches and mitigations were published; maintainers recommend upgrading to fixed versions. In addition, a 2022 “Olm/Megolm protocol confusion” advisory affecting some SDKs was critical and required client-side fixes. Use patched versions of libolm and up-to-date Matrix SDKs; avoid unpatched clients/servers.\n\nOlm is a dependency of `matrix-commander` (Python version, not Rust version).\n\nWARNING:\n\nDue to cryptographic [olm dependency deprecation](https://github.com/8go/matrix-commander/issues/204#issuecomment-3523986979), this program is cryptographically unsafe to use until https://github.com/matrix-nio/matrix-nio/pull/555 is merged. Good news: https://github.com/8go/matrix-commander-rs is a Rust alternative not having this issue.\n\n\n### References\n- CVE-2022-39255\n- CVE-2024-45193\n- https://soatok.blog/2024/08/14/security-issues-in-matrixs-olm-library/\n- https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-45193\n- https://github.com/matrix-org/matrix-ios-sdk/security/advisories/GHSA-hw6g-j8v6-9hcm\n\n### Workarounds\n- use the Rust version: https://github.com/8go/matrix-commander-rs \n\n### Severity:\n\nMedium\n\nCVE-2022-39255 — MEDIUM (NVD/MITRE lists CVSS base score 5.x — treated as Medium).\n\nCVE-2024-45193 — MEDIUM (NVD shows CVSS 3.1 base score ~4.3 — Medium)\n\n## Affected packages\n\n- `matrix-commander <= 8.0.6`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}