{"id":"CVE-2025-66622","aliases":["GHSA-jj6p-3m75-g2p3","RUSTSEC-2025-0135"],"url":"https://o3.security/vulnerability/CVE-2025-66622","summary":"matrix-sdk-base is vulnerable to DoS via custom m.room.join_rules event values","details":"The matrix-sdk-base crate is unable to handle responses that include custom m.room.join_rules values due to a serialization bug.\n\nThis can be exploited to cause a denial-of-service condition, if a user is invited to a room with non-standard join rules, the crate's sync process will stall, preventing further processing for all rooms.\n\n### Patches\nThe issue is fixed in matrix-sdk-base 0.16.0.\n\n### Workarounds\n\nUsers can leave affected rooms on another client to mitigate the issue.\n\n### References\n\nThe issue was fixed in https://github.com/matrix-org/matrix-rust-sdk/pull/5924.","published":"2025-12-09T02:07:18.831Z","modified":"2026-08-12T03:51:44.342697976Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"matrix-sdk-base","fixedVersion":"0.16.0"}],"fix":{"url":"https://github.com/matrix-org/matrix-rust-sdk/commit/4ea0418abefab2aa93f8851a4d39c723e703e6b0","label":"matrix-org/matrix-rust-sdk@4ea0418"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66622.json"},{"type":"ADVISORY","url":"https://github.com/matrix-org/matrix-rust-sdk/security/advisories/GHSA-jj6p-3m75-g2p3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-66622"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2025-0135.html"},{"type":"FIX","url":"https://github.com/matrix-org/matrix-rust-sdk/commit/4ea0418abefab2aa93f8851a4d39c723e703e6b0"},{"type":"FIX","url":"https://github.com/matrix-org/matrix-rust-sdk/pull/5924"},{"type":"PACKAGE","url":"https://github.com/matrix-org/matrix-rust-sdk"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:44.342697976Z"}}