matrix-sydent has 7 CVEs on record between 2021 and 2023. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Products
- matrix-sydent 7
7
Total CVEs
1
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2023-38686Critical· 9.3Sydent does not verify email server certificates51CVE-2021-29431High· 7.7SSRF in Sydent due to missing validation of hostnames43CVE-2019-11842High· 7.5matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG42CVE-2021-29430High· 7.5Sydent vulnerable to denial of service attack via memory exhaustion42CVE-2019-11340Medium· 5.9Matrix Sydent mishandles emails33
matrix-sydent vulnerabilities
CVEs affecting matrix-sydent, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2023-38686Critical· 9.3Sydent does not verify email server certificates
Sydent does not verify email server certificates
▾ Midnightmatrix-sydent · matrix-sydentEPSS 0.27%via OSV
CVE-2019-11842High· 7.5matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG
matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG
▾ Twilightmatrix-sydent · matrix-sydentEPSS 1.6%via OSV
CVE-2019-11340Medium· 5.9Matrix Sydent mishandles emails
Matrix Sydent mishandles emails
▾ Sunlitmatrix-sydent · matrix-sydentEPSS 2.0%via OSV
CVE-2021-29430High· 7.5Sydent vulnerable to denial of service attack via memory exhaustion
Sydent vulnerable to denial of service attack via memory exhaustion
▾ Twilightmatrix-sydent · matrix-sydentEPSS 1.8%via OSV
CVE-2021-29432Medium· 5.3Malicious users could abuse Sydent to control the content of invitation emails
Malicious users could abuse Sydent to control the content of invitation emails
▾ Sunlitmatrix-sydent · matrix-sydentEPSS 0.93%via OSV
CVE-2021-29431High· 7.7SSRF in Sydent due to missing validation of hostnames
SSRF in Sydent due to missing validation of hostnames
▾ Twilightmatrix-sydent · matrix-sydentEPSS 1.2%via OSV
CVE-2021-29433Medium· 4.3Sydent DoS (via resource exhaustion) due to improper input validation
Sydent DoS (via resource exhaustion) due to improper input validation
▾ Sunlitmatrix-sydent · matrix-sydentEPSS 0.93%via OSV