CVE-2026-63096

MEDIUM

Dendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download Endpoint

Title source: cna
STIX 2.1

Description

Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound TLS connections to arbitrary hosts and ports by supplying an unvalidated serverName parameter to the legacy media download endpoint. Attackers can exploit distinguishable error response classes and leaked internal IP addresses in error messages to perform blind port scanning and enumerate internal network topology.

Scores

CVSS v3 5.8
EPSS 0.0021
EPSS Percentile 11.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
matrix-org/dendrite < 0.13.8
Published Jul 17, 2026
Tracked Since Jul 17, 2026