alpine · CVE-2025-32026

Quick triage

Priority: low Published: Updated:

View at Official alpine advisory, NVD, CVE.org · CVE detail

Freshness: no update timestamp found; verify against the upstream OS advisory manually.

Tracker summary

CVE-2025-32026: 1 source package rows (element-web); 14 state rows across 2 repos (3.22-community, edge-community); fixed 0, open 14.

Description:

Element Web is a Matrix web client built using the Matrix React SDK. Element Web, starting from version 1.11.16 up to version 1.11.96, can be configured to load Element Call from an external URL. Under certain conditions, the external page is able to get access to the media encryption keys used for an Element Call call. Version 1.11.97 fixes the problem.

cvelogic Threat Intelligence