Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: dendrite

Found 4 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-100541
7.7 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Attack Requirement (AT): Present (P)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): High (H)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Attack Requirement (MAT): Present (P)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): High (H)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated an hour ago by @symphorien Activity log
  • Created suggestion
  • @symphorien ignored
    13 packages
    • matrix-brandy
    • matrix-conduit
    • matrix-synapse
    • matrix-tuwunel
    • matrix-corporal
    • matrix-hookshot
    • weechat-matrix-rs
    • matrix-synapse-plugins.matrix-synapse-s3-storage-provider
    • matrix-synapse-plugins.matrix-synapse-shared-secret-auth
    • matrix-synapse-plugins.matrix-synapse-mjolnir-antispam
    • matrix-synapse-plugins.matrix-http-rendezvous-synapse
    • matrix-synapse-plugins.matrix-synapse-ldap3
    • matrix-synapse-plugins.matrix-synapse-pam
OpenClaw Matrix before 2026.8.1 Authorization Bypass via Case Folding

OpenClaw's Matrix integration (npm package @openclaw/matrix) versions >= 2026.2.2 and < 2026.8.1 lowercase complete Matrix user IDs — including historical localparts and the case-sensitive server-name portion — when deriving the OpenClaw authorization identity. As a result, distinct authenticated Matrix accounts can normalize to the same authorization identity. A Matrix participant controlling a colliding account identifier (a protocol-valid identifier that differs from the configured one only by characters OpenClaw case/Unicode folds; display-name matching is not required) can inherit allowlist, owner-command, exec-approval, or plugin-approval authority configured for another account. The issue is fixed in 2026.8.1.

Affected products

matrix
  • <2026.8.1
  • ==2026.8.1

Matching in nixpkgs

pkgs.cmatrix

Simulates the falling characters theme from The Matrix movie

  • nixos-unstable -
    • nixos-unstable-small 2.0
  • nixos-26.05 -
    • nixos-26.05-small 2.0

pkgs.rmatrix

Digital rain for modern terminals

  • nixos-unstable -
    • nixos-unstable-small 0.3.3

pkgs.tmatrix

Terminal based replica of the digital rain from The Matrix

  • nixos-unstable -
    • nixos-unstable-small 1.4
  • nixos-26.05 -
    • nixos-26.05-small 1.4

pkgs.dendrite

Second-generation Matrix homeserver written in Go

  • nixos-unstable -
  • nixos-26.05 -

pkgs.gomatrix

Displays "The Matrix" in a terminal

  • nixos-unstable -
  • nixos-26.05 -

pkgs.libcmatrix

Matrix protocol library written in C using GObject

  • nixos-unstable -
    • nixos-unstable-small 0.0.4
  • nixos-26.05 -
    • nixos-26.05-small 0.0.4

pkgs.matrix-hook

Simple webhook for matrix

  • nixos-unstable -
    • nixos-unstable-small 1.0.0
  • nixos-26.05 -
    • nixos-26.05-small 1.0.0

pkgs.matrix-commander

Simple but convenient CLI-based Matrix client app for sending and receiving

  • nixos-unstable -
    • nixos-unstable-small 8.0.5
  • nixos-26.05 -
    • nixos-26.05-small 8.0.5

pkgs.matrix-media-repo

Highly configurable multi-domain media repository for Matrix

  • nixos-unstable -
    • nixos-unstable-small 1.3.8
  • nixos-26.05 -
    • nixos-26.05-small 1.3.8

pkgs.matrix-alertmanager

Bot to receive Alertmanager webhook events and forward them to chosen rooms

  • nixos-unstable -
  • nixos-26.05 -
    • nixos-26.05-small 0.9.0

pkgs.matrix-commander-rs

CLI-based Matrix client app for sending and receiving

  • nixos-unstable -
  • nixos-26.05 -
    • nixos-26.05-small 1.0.0

pkgs.matrix-continuwuity

Matrix homeserver written in Rust, forked from conduwuit

  • nixos-unstable -
  • nixos-26.05 -

pkgs.matrix-zulip-bridge

Matrix puppeting appservice bridge for Zulip

  • nixos-unstable -
    • nixos-unstable-small 0.4.1
  • nixos-26.05 -
    • nixos-26.05-small 0.4.1

pkgs.python313Packages.canmatrix

Support and convert several CAN (Controller Area Network) database formats

  • nixos-unstable -
    • nixos-unstable-small 1.2
  • nixos-26.05 -
    • nixos-26.05-small 1.2

pkgs.python314Packages.canmatrix

Support and convert several CAN (Controller Area Network) database formats

  • nixos-unstable -
    • nixos-unstable-small 1.2
  • nixos-26.05 -
    • nixos-26.05-small 1.2

pkgs.gnomeExtensions.workspace-matrix

Arrange workspaces in a two dimensional grid with workspace thumbnails.

  • nixos-unstable -
    • nixos-unstable-small 53
  • nixos-26.05 -
    • nixos-26.05-small 53
Ignored packages (13)

pkgs.matrix-brandy

Matrix Brandy BASIC VI for Linux, Windows, MacOSX

  • nixos-unstable -
  • nixos-26.05 -

pkgs.matrix-conduit

Matrix homeserver written in Rust

  • nixos-unstable -
  • nixos-26.05 -

pkgs.matrix-tuwunel

Matrix homeserver written in Rust, official successor to conduwuit

  • nixos-unstable -
    • nixos-unstable-small 1.9.2
  • nixos-26.05 -
    • nixos-26.05-small 1.9.1

pkgs.matrix-corporal

Reconciliator and gateway for a managed Matrix server

  • nixos-unstable -
    • nixos-unstable-small 2.2.0
  • nixos-26.05 -
    • nixos-26.05-small 2.2.0

pkgs.matrix-hookshot

Bridge between Matrix and multiple project management services, such as GitHub, GitLab and JIRA

  • nixos-unstable -
    • nixos-unstable-small 7.5.0
  • nixos-26.05 -
    • nixos-26.05-small 7.5.0

Package maintainers

Untriaged
Permalink CVE-2026-63095
7.1 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months ago Activity log
  • Created suggestion
Dendrite 0.13.8 Improper Authorization via POST account/3pid/delete Endpoint

Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging to other users by submitting an arbitrary address and medium to the account deletion endpoint without ownership verification. Attackers can exploit the unverified Forget3PID handler to remove a victim's email or MSISDN binding and subsequently rebind the address through an identity server to hijack the victim's password reset flow.

Affected products

dendrite
  • =<0.13.8

Matching in nixpkgs

pkgs.dendrite

Second-generation Matrix homeserver written in Go

  • nixos-unstable -
  • nixos-26.05 -
Untriaged
Permalink CVE-2026-63096
6.9 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): Low (L)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Low (L)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months ago Activity log
  • Created suggestion
Dendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download Endpoint

Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound TLS connections to arbitrary hosts and ports by supplying an unvalidated serverName parameter to the legacy media download endpoint. Attackers can exploit distinguishable error response classes and leaked internal IP addresses in error messages to perform blind port scanning and enumerate internal network topology.

Affected products

dendrite
  • =<0.13.8

Matching in nixpkgs

pkgs.dendrite

Second-generation Matrix homeserver written in Go

  • nixos-unstable -
  • nixos-26.05 -
Untriaged
Permalink CVE-2026-63097
5.3 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 2 months ago Activity log
  • Created suggestion
Dendrite 0.13.8 syncapi /context Endpoint Post-Leave State Exposure

Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/routing/context.go) that allows authenticated local users to access post-leave room state events by exploiting a flawed membership check that evaluates only the RoomExists field while ignoring IsInRoom, HasBeenInRoom, and Membership fields. Attackers who have left a room can call the rooms context API endpoint for a previously permitted event and receive unfiltered current room state that the /messages and /sync endpoints correctly withhold.

Affected products

dendrite
  • =<0.13.8

Matching in nixpkgs

pkgs.dendrite

Second-generation Matrix homeserver written in Go

  • nixos-unstable -
  • nixos-26.05 -