VYPR

Dendrite

by Dendrite

CVEs (3)

  • CVE-2026-63097Jul 17, 2026
    risk 0.00cvss epss 0.00

    Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/routing/context.go) that allows authenticated local users to access post-leave room state events by exploiting a flawed membership check that evaluates only the…

  • CVE-2026-63096Jul 17, 2026
    risk 0.00cvss epss 0.00

    Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound TLS connections to arbitrary hosts and ports by supplying an unvalidated serverName parameter to the legacy media download…

  • CVE-2026-63095Jul 17, 2026
    risk 0.00cvss epss 0.00

    Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging to other users by submitting an arbitrary address and medium to the account…