GHSA-9jhm-8m8c-c3f4 · Severity: medium · Ecosystem: pip — SSRF in Sydent due to missing validation of hostnames
Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter validation or IP address blacklisting. It is not possible to exfiltrate data or control request headers, but it might be possible to use the attack to perform an internal port enumeration. This issue has been addressed in in 9e57334, 8936925, 3d531ed, 0f00412. A potential workaround would be to use a firewall to ensure that Sydent cannot reach internal HTTP resources.
Conclusion & alert: CVE-2021-29431 is rated Moderate Risk (54.1/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.19%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.30% | 1.19% | +0.89% |
| 2 | 2025-11-21 | 0.35% | 0.30% | -0.05% |
| 3 | 2025-11-18 | — | 0.35% | — |
Full EPSS history (12 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.7 | 3.1 | HIGH |
|
3.1 | 4.0 | [email protected] |
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
| 4.0 | 2.0 | MEDIUM |
|
8.0 | 2.9 | [email protected] |
GHSA-9jhm-8m8c-c3f4 · Severity: medium · Ecosystem: pip — SSRF in Sydent due to missing validation of hostnames
| URL | Tags |
|---|---|
| https://github.com/matrix-org/sydent/commit/0f00412017f25619bc36c264b29ea96808bf310a | Patch Third Party Advisory |
| https://github.com/matrix-org/sydent/commit/3d531ed50d2fd41ac387f36d44d3fb2c62dd22d3 | Patch Third Party Advisory |
| https://github.com/matrix-org/sydent/commit/8936925f561b0c352c2fa922d5097d7245aad00a | Patch Third Party Advisory |
| https://github.com/matrix-org/sydent/commit/9e573348d81df8191bbe8c266c01999c9d57cd5f | Patch Third Party Advisory |
| https://github.com/matrix-org/sydent/releases/tag/v2.3.0 | Release Notes Third Party Advisory |
| https://github.com/matrix-org/sydent/security/advisories/GHSA-9jhm-8m8c-c3f4 | Patch Third Party Advisory |
| https://pypi.org/project/matrix-sydent/ | Product Third Party Advisory |