PT-2026-60789 · Git+1 · Dendrite

·

CVE-2026-63096

·

Published

2026-07-17

·

Updated

2026-07-17

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Dendrite versions prior to 0.13.9
Description A server-side request forgery (SSRF) issue allows unauthenticated attackers to force the server to establish outbound TLS connections to arbitrary hosts and ports. This is achieved by providing an unvalidated serverName parameter to the legacy media download endpoint. Attackers can use distinguishable error response classes and internal IP addresses leaked in error messages to conduct blind port scanning and map the internal network topology.
Recommendations Update to version 0.13.9 or later. As a temporary mitigation, restrict access to the legacy media download endpoint.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63096

Affected Products

Dendrite