CVE-2025-66622: matrix-sdk-base is vulnerable to DoS via custom m.room.join_rules event values

Published Dec 8, 2025
·
Updated

matrix-sdk-base is the base component to build a Matrix client library. Versions 0.14.1 and prior are unable to handle responses that include custom m.room.joinrules values due to a serialization bug. This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms. This is fixed in version 0.16.0.

Other sources

The matrix-sdk-base crate is unable to handle responses that include custom m.room.joinrules values due to a serialization bug.

This can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms.

Patches The issue is fixed in matrix-sdk-base 0.16.0.

Workarounds

Users can leave affected rooms on another client to mitigate the issue.

References

The issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924.

GitHub

Affected Software

2 affected componentsFixes available
rust/matrix-sdk-base<0.16.0
0.16.0
matrix matrix-rust-sdk<0.16.0

Event History

Dec 8, 2025
Advisory Published
via GitHub·10:07 PM
Data Sourced
via GitHub·10:07 PM
DescriptionWeaknessAffected Software
Dec 9, 2025
CVE Published
via MITRE·02:07 AM
Data Sourced
via MITRE·02:07 AM
DescriptionWeakness
Data Sourced
via NVD·04:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 PM
RemedyAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-66622?

CVE-2025-66622 has been classified as a denial-of-service vulnerability due to its ability to stall the sync process.

2

How do I fix CVE-2025-66622?

To mitigate CVE-2025-66622, upgrading to matrix-sdk-base version 0.16.0 or later is recommended.

3

What causes CVE-2025-66622?

CVE-2025-66622 is caused by a serialization bug that affects the handling of custom m.room.join_rules values.

4

What software is affected by CVE-2025-66622?

CVE-2025-66622 affects the matrix-sdk-base crate prior to version 0.16.0.

5

What happens if I am impacted by CVE-2025-66622?

If impacted by CVE-2025-66622, users may experience denied service due to stalled sync processes when invited to rooms with non-standard join rules.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203