CVE-2025-66622 is a denial-of-service vulnerability affecting matrix-sdk-base versions 0.14.1 and prior. A serialization bug prevents the software from properly handling custom m.room.join_rules values, causing the sync process to stall if a user is invited to a room with non-standard join rules. This vulnerability has a low CVSS score of 1.3, indicating a low attack complexity and impact, as it requires user interaction (UI:P) and only leads to a low availability impact (VA:L). There is currently no known active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.16.0CPE matchmatch criteria | cpe:2.3:a:matrix:matrix-rust-sdk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.