{"id":"RUSTSEC-2026-0318","aliases":["GHSA-45pr-7vv7-f64m"],"title":"Sending custom to-device messages may panics","summary":"Sending custom to-device messages may panics","severity":"none","vendor":"matrix-sdk-crypto","product":"matrix-sdk-crypto","ecosystem":"rust","affected":["matrix-sdk-crypto >= 0.0.0-0, < 0.19.0"],"patched":["matrix-sdk-crypto 0.19.0"],"published":"2026-09-29","updated":"2026-10-01","sourceUpdated":"2026-10-01T20:30:02.687839486Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0318","references":[{"url":"https://crates.io/crates/matrix-sdk-crypto"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0318.html"},{"url":"https://github.com/matrix-org/matrix-rust-sdk/pull/6670"},{"url":"https://github.com/matrix-org/matrix-rust-sdk/commit/01b45b51299821ab03fecf46741392780f118d49"}],"tags":["osv","rust"],"ingestedAt":"2026-10-02T07:24:14.793Z","slug":"RUSTSEC-2026-0318","body":"## Overview\n\nUsing the `IdentityBasedStrategy` setting when calling\n`Device::encrypt_event_raw` or `OlmMachine::encrypt_content_for_devices` may\ncause a panic if the recipient does not have cross-signing keys.\n\n## Affected packages\n\n- `matrix-sdk-crypto >= 0.0.0-0, < 0.19.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `matrix-sdk-crypto 0.19.0`","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}