Impact
Dendrite through version 0.13.8 contains a server‑side request forgery that permits unauthenticated attackers to instruct the server to establish outbound TLS connections to any host and port by supplying an unvalidated serverName parameter to the legacy media download endpoint. By observing distinct error response classes and leaked internal IP addresses in the error messages, an attacker can effectively conduct blind port scanning and map out internal network topology, potentially exposing sensitive services or creating footholds for further exploitation.
Affected Systems
Matrix‑Org’s Dendrite matrix‑org:dendrite, with all releases up to and including 0.13.8 vulnerable. No newer versions are listed as affected.
Risk and Exploitability
The CVSS score of 6.9 reflects a moderate severity assessment, while the EPSS score of less than 1% indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers can trigger the flaws by sending unauthenticated HTTP requests to the /_matrix/media/r0/download endpoint with an arbitrary serverName parameter; no prior authentication or privileged access is required.
OpenCVE Enrichment