CVE-2026-63096 | matrix-org dendrite up to 0.13.8 Legacy Media Download Endpoint servername server-side request forgery (EUVD-2026-45194)
A vulnerability was found in matrix-org dendrite up to 0.13.8. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the component Legacy Media Download Endpoint. The manipulation of the argument servername leads to server-side request forgery. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is documented as CVE-2026-63096. The attack can be initiated remotely. There is not any exploit available.