Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. matrix-commander
  4. ›
  5. GHSA-wchh-9x6h-7f6p

GHSA-wchh-9x6h-7f6p: olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193

July 29, 2026

Problem

Multiple vulnerabilities were disclosed in 2024 affecting libolm (Olm): AES timing / side‑channel, Ed25519 signature malleability, and timing leaks in base64 decoding; several CVEs were assigned. Patches and mitigations were published; maintainers recommend upgrading to fixed versions. In addition, a 2022 “Olm/Megolm protocol confusion” advisory affecting some SDKs was critical and required client-side fixes. Use patched versions of libolm and up-to-date Matrix SDKs; avoid unpatched clients/servers.

Olm is a dependency of matrix-commander (Python version, not Rust version).

WARNING:

Due to cryptographic olm dependency deprecation, this program is cryptographically unsafe to use until https://github.com/matrix-nio/matrix-nio/pull/555 is merged. Good news: https://github.com/8go/matrix-commander-rs is a Rust alternative not having this issue.

References

  • CVE-2022-39255
  • CVE-2024-45193
  • https://soatok.blog/2024/08/14/security-issues-in-matrixs-olm-library/
  • https://nvd.nist.gov/nvd.cfm?cvename=CVE-2024-45193
  • https://github.com/matrix-org/matrix-ios-sdk/security/advisories/GHSA-hw6g-j8v6-9hcm

Workarounds

  • use the Rust version: https://github.com/8go/matrix-commander-rs

Severity:

Medium

CVE-2022-39255 — MEDIUM (NVD/MITRE lists CVSS base score 5.x — treated as Medium).

CVE-2024-45193 — MEDIUM (NVD shows CVSS 3.1 base score ~4.3 — Medium)

References

  • github.com/8go/matrix-commander/issues/204
  • github.com/8go/matrix-commander/security/advisories/GHSA-wchh-9x6h-7f6p
  • github.com/advisories/GHSA-wchh-9x6h-7f6p
  • github.com/matrix-nio/matrix-nio/commit/71a1c808bc2ae6ea2a6e8effa7c11bd09796c626
  • github.com/matrix-nio/matrix-nio/pull/555

Code Behaviors & Features

Detect and mitigate GHSA-wchh-9x6h-7f6p with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 8.0.6

Solution

Unfortunately, there is no solution available yet.

Weakness

  • CWE-1395: Dependency on Vulnerable Third-Party Component

Source file

pypi/matrix-commander/GHSA-wchh-9x6h-7f6p.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:17:39 +0000.