Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-29431

22
FAUCET Score

CVE-2021-29431 affects Sydent, the reference Matrix identity server, allowing it to be coerced into sending HTTP GET requests to internal systems due to insufficient parameter validation. This medium-severity vulnerability (CVSS 6.5) could enable internal port enumeration, but does not permit data exfiltration or control over request headers. While a fix has been released, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this issue.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.3.0CPE matchmatch criteria
cpe:2.3:a:matrix:sydent:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.7HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.1
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.19%
Probability of exploitation in next 30 days
EPSS Percentile
64.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0119 is in the 79th percentile among its peer group of 21,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: matrix-sydentFixed in: 2.3.0

Vendor Advisories (1)

pipGHSA-9jhm-8m8c-c3f4medium

SSRF in Sydent due to missing validation of hostnames

Apr 19, 2021

References

github.com / matrix-org/sydent/commit/0f00412017f25619bc36c264b29ea96808bf310a
PatchThird Party Advisory
github.com / matrix-org/sydent/commit/3d531ed50d2fd41ac387f36d44d3fb2c62dd22d3
PatchThird Party Advisory
github.com / matrix-org/sydent/commit/8936925f561b0c352c2fa922d5097d7245aad00a
PatchThird Party Advisory
github.com / matrix-org/sydent/commit/9e573348d81df8191bbe8c266c01999c9d57cd5f
PatchThird Party Advisory
github.com / matrix-org/sydent/releases/tag/v2.3.0
Release NotesThird Party Advisory
github.com / matrix-org/sydent/security/advisories/GHSA-9jhm-8m8c-c3f4
PatchThird Party Advisory
pypi.org / project/matrix-sydent
ProductThird Party Advisory