matrix-sdk-base is vulnerable to Undefined Behavior
25
Low Risk
Affected versions of this package are vulnerable to a Denial of Service (DoS) in the RoomMember::normalized_power_level() method. A specially crafted room member with a power level set to Int::MIN can trigger a panic, leading to application crash and service unavailability.
You are affected if you are using a version that falls within the vulnerable range.
matrix-sdk-base is vulnerable to Undefined Behavior in versions 0.1.0 - 0.14.0.
Upgrade the matrix-sdk-base library to the patch version or avoid calling RoomMember::normalized_power_level().
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant