People can't help but try to evangelize Matrix in response to things I wrote, so I just disclosed a few more issues in Matrix's cryptography to their security@ email address.
This time, the issues were in their Rust library, vodozemac.
One of them was pretty fucking stupid.
I'll do a better write-up than I was initially planning when they've had time to fix it.