GHSA-wchh-9x6h-7f6pMedium▾ Sunlitolm dependency deprecation: CVE-2022-39255 and CVE-2024-45193
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Multiple vulnerabilities were disclosed in 2024 affecting libolm (Olm): AES timing / side‑channel, Ed25519 signature malleability, and timing leaks in base64 decoding; several CVEs were assigned. Patches and mitigations were published; maintainers recommend upgrading to fixed versions. In addition, a 2022 “Olm/Megolm protocol confusion” advisory affecting some SDKs was critical and required client-side fixes. Use patched versions of libolm and up-to-date Matrix SDKs; avoid unpatched clients/servers.
Olm is a dependency of matrix-commander (Python version, not Rust version).
WARNING:
Due to cryptographic olm dependency deprecation, this program is cryptographically unsafe to use until https://github.com/matrix-nio/matrix-nio/pull/555 is merged. Good news: https://github.com/8go/matrix-commander-rs is a Rust alternative not having this issue.
Medium
CVE-2022-39255 — MEDIUM (NVD/MITRE lists CVSS base score 5.x — treated as Medium).
CVE-2024-45193 — MEDIUM (NVD shows CVSS 3.1 base score ~4.3 — Medium)
matrix-commander <= 8.0.6Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
GHSA-537c-gmf6-5ccfHigh· 7.5Vulnerable OpenSSL included in cryptography wheels
CVE-2026-90455Medium· 6.3A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component
GHSA-2xp9-vwfh-vxw4CriticalNext.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
CVE-2026-69713Medium· 4.4Dependency on vulnerable third-party component in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
GHSA-f88m-g3jw-g9cjHighsharp inherited vulnerabilities in libvips: CVE-2026-33327, CVE-2026-33328, CVE-2026-35590, CVE-2026-35591
GHSA-q7j3-v8qv-22vqHigh· 7.5OpenTofu: Possible arbitrary file read during certain git operations via a maliciously crafted URL