Matrix Dendrite是Matrix基金会开源的一个用 Go 编写的第二代 Matrix 家庭服务器。 Matrix Dendrite 0.13.8及之前版本存在服务端请求伪造漏洞,该漏洞源于服务端请求伪造问题,可能导致未经身份验证的攻击者通过向旧的媒体下载端点提供未经验证的serverName参数,使服务器打开对任意主机和端口的出站TLS连接,并利用可区分的错误响应类和泄露的内部IP地址执行盲端口扫描和枚举内部网络拓扑。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| matrix-org | dendrite | ≤ 0.13.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| matrix-org | dendrite | 0 ~ 0.13.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63095 | 6.5 MEDIUM | Dendrite 0.13.8 Improper Authorization via POST account/3pid/delete Endpoint |
| CVE-2026-63097 | 4.3 MEDIUM | Dendrite 0.13.8 syncapi /context Endpoint Post-Leave State Exposure |
No comments yet