Matrix Dendrite是Matrix基金会开源的一个用 Go 编写的第二代 Matrix 家庭服务器。 Matrix Dendrite 0.13.8及之前版本存在授权问题漏洞,该漏洞源于syncapi/context端点中的访问控制不当,允许经过身份验证的用户通过利用仅检查RoomExists字段而忽略IsInRoom、HasBeenInRoom和Membership字段的成员身份检查来访问离开房间后的状态事件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| matrix-org | dendrite | ≤ 0.13.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| matrix-org | dendrite | 0 ~ 0.13.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63095 | 6.5 MEDIUM | Dendrite 0.13.8 Improper Authorization via POST account/3pid/delete Endpoint |
| CVE-2026-63096 | 5.8 MEDIUM | Dendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download Endpoint |
No comments yet