Dendrite Matrix Dendrite

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Matrix Dendrite.

By the Year

In 2026 there have been 3 vulnerabilities in Matrix Dendrite with an average score of 5.5 out of ten. Dendrite did not have any published security vulnerabilities last year. That is, 3 more vulnerabilities have already been reported in 2026 as compared to last year.

Year Vulnerabilities Average Score
2026 3 5.53
2025 0 0.00
2024 0 0.00
2023 0 0.00
2022 2 7.05

It may take a day or so for new Dendrite vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Matrix Dendrite Security Vulnerabilities

Improper Access Control in Dendrite <=0.13.8 SyncAPI Context Endpoint
CVE-2026-63097 4.3 - Medium - July 17, 2026

Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/routing/context.go) that allows authenticated local users to access post-leave room state events by exploiting a flawed membership check that evaluates only the RoomExists field while ignoring IsInRoom, HasBeenInRoom, and Membership fields. Attackers who have left a room can call the rooms context API endpoint for a previously permitted event and receive unfiltered current room state that the /messages and /sync endpoints correctly withhold.

AuthZ

S2S Request Forgery in Dendrite 0.13.8 Enables Blind Port Scanning
CVE-2026-63096 5.8 - Medium - July 17, 2026

Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound TLS connections to arbitrary hosts and ports by supplying an unvalidated serverName parameter to the legacy media download endpoint. Attackers can exploit distinguishable error response classes and leaked internal IP addresses in error messages to perform blind port scanning and enumerate internal network topology.

SSRF

Dendrite <=0.13.8 Improper Auth: Delete Other Users' 3PID via Forget3PID
CVE-2026-63095 6.5 - Medium - July 17, 2026

Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging to other users by submitting an arbitrary address and medium to the account deletion endpoint without ownership verification. Attackers can exploit the unverified Forget3PID handler to remove a victim's email or MSISDN binding and subsequently rebind the address through an identity server to hijack the victim's password reset flow.

Insecure Direct Object Reference / IDOR

Sig Verify Bypass in Matrix Dendrite 0.9.x /get_missing_events
CVE-2022-39200 5.3 - Medium - September 12, 2022

Dendrite is a Matrix homeserver written in Go. In affected versions events retrieved from a remote homeserver using the `/get_missing_events` path did not have their signatures verified correctly. This could potentially allow a remote homeserver to provide invalid/modified events to Dendrite via this endpoint. Note that this does not apply to events retrieved through other endpoints (e.g. `/event`, `/state`) as they have been correctly verified. Homeservers that have federation disabled are not vulnerable. The problem has been fixed in Dendrite 0.9.8. Users are advised to upgrade. There are no known workarounds for this issue.

Improper Verification of Cryptographic Signature

gomatrixserverlib Go lib (before 0.9.3) event parsing flaw CVE-2022-36009
CVE-2022-36009 8.8 - High - August 19, 2022

gomatrixserverlib is a Go library for matrix protocol federation. Dendrite is a Matrix homeserver written in Go, an alternative to Synapse. The power level parsing within gomatrixserverlib was failing to parse the `"events_default"` key of the `m.room.power_levels` event, defaulting the event default power level to zero in all cases. Power levels are the matrix terminology for user access level. In rooms where the `"events_default"` power level had been changed, this could result in events either being incorrectly authorised or rejected by Dendrite servers. gomatrixserverlib contains a fix as of commit `723fd49` and Dendrite 0.9.3 has been updated accordingly. Matrix rooms where the `"events_default"` power level has not been changed from the default of zero are not vulnerable. Users are advised to upgrade. There are no known workarounds for this issue.

AuthZ

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Matrix Dendrite or by Matrix? Click the Watch button to subscribe.

Matrix
Vendor

subscribe