CVE-2026-63096

Source
https://cve.org/CVERecord?id=CVE-2026-63096
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63096.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63096
Published
2026-07-17T15:30:28.771Z
Modified
2026-07-19T03:47:18.259284084Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N CVSS Calculator
Summary
Dendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download Endpoint
Details

Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound TLS connections to arbitrary hosts and ports by supplying an unvalidated serverName parameter to the legacy media download endpoint. Attackers can exploit distinguishable error response classes and leaked internal IP addresses in error messages to perform blind port scanning and enumerate internal network topology.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63096.json",
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-918"
    ]
}
References

Affected packages

Git / github.com/matrix-org/dendrite

Affected ranges

Type
GIT
Repo
https://github.com/matrix-org/dendrite
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.13.8"
        }
    ]
}

Affected versions

helm-dendrite-0.*
helm-dendrite-0.10.8
helm-dendrite-0.10.9
helm-dendrite-0.11.0
helm-dendrite-0.11.1
helm-dendrite-0.11.2
helm-dendrite-0.12.0
helm-dendrite-0.12.1
helm-dendrite-0.12.2
helm-dendrite-0.12.3
helm-dendrite-0.12.4
helm-dendrite-0.13.0
helm-dendrite-0.13.1
helm-dendrite-0.13.2
helm-dendrite-0.13.3
helm-dendrite-0.13.4
helm-dendrite-0.13.5
helm-dendrite-0.13.6
helm-dendrite-0.13.7
helm-dendrite-0.13.8
helm-dendrite-0.14.0
helm-dendrite-0.14.1
helm-dendrite-0.14.2
v0.*
v0.1.0
v0.10.0
v0.10.1
v0.10.2
v0.10.3
v0.10.4
v0.10.5
v0.10.6
v0.10.7
v0.10.8
v0.10.9
v0.11.0
v0.11.1
v0.12.0
v0.13.0
v0.13.1
v0.13.2
v0.13.3
v0.13.4
v0.13.5
v0.13.6
v0.13.7
v0.13.8
v0.2.0
v0.2.1
v0.3.0
v0.3.1
v0.3.10
v0.3.11
v0.3.2
v0.3.3
v0.3.4
v0.3.5
v0.3.6
v0.3.7
v0.3.8
v0.3.9
v0.4.0
v0.4.1
v0.5.0
v0.5.0rc1
v0.5.1
v0.6
v0.6.0
v0.6.1
v0.6.2
v0.6.3
v0.6.4
v0.6.5
v0.7.0
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.8.3rc1
v0.8.4
v0.8.5
v0.8.6
v0.8.7
v0.8.8
v0.8.9
v0.9.0
v0.9.1
v0.9.2
v0.9.3
v0.9.4
v0.9.5
v0.9.6
v0.9.7
v0.9.8
v0.9.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63096.json"