CVE-2026-63097

Source
https://cve.org/CVERecord?id=CVE-2026-63097
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63097.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63097
Published
2026-07-17T15:32:45.411Z
Modified
2026-07-19T03:47:18.368776373Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Dendrite 0.13.8 syncapi /context Endpoint Post-Leave State Exposure
Details

Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/routing/context.go) that allows authenticated local users to access post-leave room state events by exploiting a flawed membership check that evaluates only the RoomExists field while ignoring IsInRoom, HasBeenInRoom, and Membership fields. Attackers who have left a room can call the rooms context API endpoint for a previously permitted event and receive unfiltered current room state that the /messages and /sync endpoints correctly withhold.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63097.json",
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-863"
    ]
}
References

Affected packages

Git / github.com/matrix-org/dendrite

Affected ranges

Type
GIT
Repo
https://github.com/matrix-org/dendrite
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.13.8"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

helm-dendrite-0.*
helm-dendrite-0.10.8
helm-dendrite-0.10.9
helm-dendrite-0.11.0
helm-dendrite-0.11.1
helm-dendrite-0.11.2
helm-dendrite-0.12.0
helm-dendrite-0.12.1
helm-dendrite-0.12.2
helm-dendrite-0.12.3
helm-dendrite-0.12.4
helm-dendrite-0.13.0
helm-dendrite-0.13.1
helm-dendrite-0.13.2
helm-dendrite-0.13.3
helm-dendrite-0.13.4
helm-dendrite-0.13.5
helm-dendrite-0.13.6
helm-dendrite-0.13.7
helm-dendrite-0.13.8
helm-dendrite-0.14.0
helm-dendrite-0.14.1
helm-dendrite-0.14.2
v0.*
v0.1.0
v0.10.0
v0.10.1
v0.10.2
v0.10.3
v0.10.4
v0.10.5
v0.10.6
v0.10.7
v0.10.8
v0.10.9
v0.11.0
v0.11.1
v0.12.0
v0.13.0
v0.13.1
v0.13.2
v0.13.3
v0.13.4
v0.13.5
v0.13.6
v0.13.7
v0.13.8
v0.2.0
v0.2.1
v0.3.0
v0.3.1
v0.3.10
v0.3.11
v0.3.2
v0.3.3
v0.3.4
v0.3.5
v0.3.6
v0.3.7
v0.3.8
v0.3.9
v0.4.0
v0.4.1
v0.5.0
v0.5.0rc1
v0.5.1
v0.6
v0.6.0
v0.6.1
v0.6.2
v0.6.3
v0.6.4
v0.6.5
v0.7.0
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.8.3rc1
v0.8.4
v0.8.5
v0.8.6
v0.8.7
v0.8.8
v0.8.9
v0.9.0
v0.9.1
v0.9.2
v0.9.3
v0.9.4
v0.9.5
v0.9.6
v0.9.7
v0.9.8
v0.9.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63097.json"