Vulnerability DatabaseGHSA-fc4h-xcf3-qj5f

GHSA-fc4h-xcf3-qj5f
Rust vulnerability analysis and mitigation

Overview

The vulnerability (GHSA-fc4h-xcf3-qj5f) affects matrix-sdk versions 0.6.0 to 0.6.2 and was discovered in October 2022. The issue involves the unintended logging of user access tokens when using matrix-sdk with tracing-subscriber in applications. This moderate severity vulnerability was officially published to the GitHub Advisory Database on October 25, 2022, and received its last update on January 7, 2023 (GitHub Advisory, RustSec Advisory).

Technical details

The vulnerability occurs when sending Matrix requests using the affected versions of matrix-sdk in applications that implement logging with tracing-subscriber. Specifically, when the logging configuration includes fields of tracing spans, such as the default text output from the fmt module, the logs inadvertently expose the user's access token. This issue was documented in detail through practical examples showing how the access tokens appear in log outputs (Matrix SDK Issue).

Impact

The primary impact of this vulnerability is the exposure of user access tokens in application logs. Access tokens are sensitive authentication credentials, and their exposure in logs could potentially lead to unauthorized access to user accounts if the logs are compromised or inadvertently shared (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in matrix-sdk version 0.6.2. Users should upgrade to this version or later to prevent the exposure of access tokens in logs. Systems running versions prior to 0.6.0 are not affected by this vulnerability (GitHub Advisory, RustSec Advisory).

Additional resources


SourceThis report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22863CRITICAL9.2
  • RustRust
  • deno
NoYesJan 15, 2026
CVE-2026-23519HIGH8.9
  • RustRust
  • yazi
NoYesJan 15, 2026
RUSTSEC-2026-0003HIGH8.9
  • RustRust
  • cmov
NoYesJan 14, 2026
CVE-2026-22864HIGH8.1
  • RustRust
  • deno
NoYesJan 15, 2026
CVE-2026-22782LOW2.9
  • RustRust
  • rustfs
NoYesJan 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management