VYPR

Gomatrixserverlib

by Matrix Org

Source repositories

CVEs (1)

  • CVE-2024-52594MedJan 16, 2025
    risk 0.21cvss 4.3epss 0.00

    Gomatrixserverlib is a Go library for matrix federation. Gomatrixserverlib is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. The commit `c4f1e01` fixes this issue. Users are advised to upgrade. Users unable to upgrade should use a local firewall to limit the network segments and hosts the service using gomatrixserverlib can access.