---
id: RUSTSEC-2026-0318
aliases:
  - GHSA-45pr-7vv7-f64m
title: Sending custom to-device messages may panics
summary: Sending custom to-device messages may panics
severity: none
vendor: matrix-sdk-crypto
product: matrix-sdk-crypto
ecosystem: rust
affected:
  - 'matrix-sdk-crypto >= 0.0.0-0, < 0.19.0'
patched:
  - matrix-sdk-crypto 0.19.0
published: '2026-09-29'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T20:30:02.687839486Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/RUSTSEC-2026-0318'
references:
  - url: 'https://crates.io/crates/matrix-sdk-crypto'
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0318.html'
  - url: 'https://github.com/matrix-org/matrix-rust-sdk/pull/6670'
  - url: >-
      https://github.com/matrix-org/matrix-rust-sdk/commit/01b45b51299821ab03fecf46741392780f118d49
tags:
  - osv
  - rust
ingestedAt: '2026-10-02T07:24:14.793Z'
---

## Overview

Using the `IdentityBasedStrategy` setting when calling
`Device::encrypt_event_raw` or `OlmMachine::encrypt_content_for_devices` may
cause a panic if the recipient does not have cross-signing keys.

## Affected packages

- `matrix-sdk-crypto >= 0.0.0-0, < 0.19.0`

## Remediation

Upgrade to a patched release:

- `matrix-sdk-crypto 0.19.0`
