matrix-sydent vulnerabilities
CVEs whose affected-version data names the matrix-sydent package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
7 CVEsRSS
CVE-2023-38686Critical· 9.3Sydent does not verify email server certificates
Sydent does not verify email server certificates
▾ Midnightmatrix-sydent · matrix-sydentEPSS 0.27%via OSV
CVE-2019-11842High· 7.5matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG
matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG
▾ Twilightmatrix-sydent · matrix-sydentEPSS 1.6%via OSV
CVE-2019-11340Medium· 5.9Matrix Sydent mishandles emails
Matrix Sydent mishandles emails
▾ Sunlitmatrix-sydent · matrix-sydentEPSS 2.0%via OSV
CVE-2021-29430High· 7.5Sydent vulnerable to denial of service attack via memory exhaustion
Sydent vulnerable to denial of service attack via memory exhaustion
▾ Twilightmatrix-sydent · matrix-sydentEPSS 1.8%via OSV
CVE-2021-29432Medium· 5.3Malicious users could abuse Sydent to control the content of invitation emails
Malicious users could abuse Sydent to control the content of invitation emails
▾ Sunlitmatrix-sydent · matrix-sydentEPSS 0.93%via OSV
CVE-2021-29431High· 7.7SSRF in Sydent due to missing validation of hostnames
SSRF in Sydent due to missing validation of hostnames
▾ Twilightmatrix-sydent · matrix-sydentEPSS 1.2%via OSV
CVE-2021-29433Medium· 4.3Sydent DoS (via resource exhaustion) due to improper input validation
Sydent DoS (via resource exhaustion) due to improper input validation
▾ Sunlitmatrix-sydent · matrix-sydentEPSS 0.93%via OSV