CVE-2022-39200
Dendrite is a Matrix homeserver written in Go. In affected versions events retrieved from a remote homeserver using the `/get_missing_events` path did not have their signatures verified correctly. This could potentially allow a remote homeserver to provide invalid/modified events to Dendrite via this endpoint. Note that this does not apply to events retrieved through other endpoints (e.g. `/event`, `/state`) as they have been correctly verified. Homeservers that have federation disabled are not vulnerable. The problem has been fixed in Dendrite 0.9.8. Users are advised to upgrade. There are no known workarounds for this issue.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.36%
- Percentil entre todas las CVEs puntuadas: 28
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-347
Referencias
- https://github.com/matrix-org/dendrite/commit/2792d0490f3771488bad346981b8c26479a872c3
- https://github.com/matrix-org/dendrite/security/advisories/GHSA-pfw4-xjgm-267c
- https://github.com/matrix-org/dendrite/commit/2792d0490f3771488bad346981b8c26479a872c3
- https://github.com/matrix-org/dendrite/security/advisories/GHSA-pfw4-xjgm-267c
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-39200",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-39200",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-04-23T15:51:38.411146Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.3,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 3.4,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "matrix-org",
"product": "dendrite",
"versions": [
{
"status": "affected",
"version": "< 0.9.8"
}
]
}
]
}
],
"published": "2022-09-12T20:15:12.960",
"references": [
{
"url": "https://github.com/matrix-org/dendrite/commit/2792d0490f3771488bad346981b8c26479a872c3",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/matrix-org/dendrite/security/advisories/GHSA-pfw4-xjgm-267c",
"tags": [
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/matrix-org/dendrite/commit/2792d0490f3771488bad346981b8c26479a872c3",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/matrix-org/dendrite/security/advisories/GHSA-pfw4-xjgm-267c",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-347"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Dendrite is a Matrix homeserver written in Go. In affected versions events retrieved from a remote homeserver using the `/get_missing_events` path did not have their signatures verified correctly. This could potentially allow a remote homeserver to provide invalid/modified events to Dendrite via this endpoint. Note that this does not apply to events retrieved through other endpoints (e.g. `/event`, `/state`) as they have been correctly verified. Homeservers that have federation disabled are not vulnerable. The problem has been fixed in Dendrite 0.9.8. Users are advised to upgrade. There are no known workarounds for this issue."
},
{
"lang": "es",
"value": "Dendrite es un servidor doméstico de Matrix escrito en Go. En las versiones afectadas, los eventos recuperados de un servidor doméstico remoto usando la ruta \"/get_missing_events\" no presentaban sus firmas verificadas correctamente. Esto podría permitir que un servidor doméstico remoto proporcionara eventos no válidos/modificados a Dendrite por medio de este endpoint. Ten en cuenta que esto no es aplicado a eventos recuperados mediante otros endpoints (por ejemplo, \"/event\", \"/state\") ya que han sido correctamente verificados. Los servidores domésticos que presentan la federación deshabilitada no son vulnerables. El problema ha sido corregido en Dendrite versión 0.9.8. Es recomendado a usuarios actualizar. No se presentan mitigaciones conocidas para este problema"
}
],
"lastModified": "2026-06-17T04:57:54.137",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:matrix:dendrite:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6C742B40-80E7-4128-A0D0-26585D60D546",
"versionEndExcluding": "0.9.8"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}