{"schema_version":1,"title":"matrix-sydent (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 7 vulnerabilities in matrix-sydent (PyPI): 0 in the last 7 days and 2 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2019-11842, was published on 9 July 2026.","url":"https://junglewise.ai/threats/technologies/matrix-sydent","json_url":"https://junglewise.ai/threats/technologies/matrix-sydent.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/matrix-sydent","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":7,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":2,"last_365_days":2},"latest":[{"cve":"CVE-2019-11842","cvss":3,"epss":0.018,"slug":"cve-2019-11842-matrix-sydent-and-matrix-synapse-use-cryptographically-weak-prng","title":"PYSEC-2026-2620 - matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG","severity":"low","exploited":false,"published_at":"2026-07-09T16:49:47.132995+00:00","url":"https://junglewise.ai/threats/cve-2019-11842-matrix-sydent-and-matrix-synapse-use-cryptographically-weak-prng"},{"cve":"CVE-2019-11340","cvss":3,"epss":0.0188,"slug":"cve-2019-11340-matrix-sydent-mishandles-emails","title":"PYSEC-2026-843 - Matrix Sydent mishandles emails","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:28.015702+00:00","url":"https://junglewise.ai/threats/cve-2019-11340-matrix-sydent-mishandles-emails"},{"cve":"CVE-2023-38686","cvss":3.1,"epss":0.0027,"slug":"cve-2023-38686-sydent-does-not-verify-email-server-certificates","title":"PYSEC-2023-139 - Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send emails using TLS, Sydent","severity":"low","exploited":false,"published_at":"2023-08-04T16:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-38686-sydent-does-not-verify-email-server-certificates"},{"cve":"CVE-2021-29432","cvss":3.1,"epss":0.0093,"slug":"cve-2021-29432-malicious-users-could-abuse-sydent-to-control-the-content-of","title":"PYSEC-2021-23 - Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address","severity":"low","exploited":false,"published_at":"2021-04-15T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-29432-malicious-users-could-abuse-sydent-to-control-the-content-of"},{"cve":"CVE-2021-29431","cvss":3.1,"epss":0.0119,"slug":"cve-2021-29431-ssrf-in-sydent-due-to-missing-validation-of-hostnames","title":"PYSEC-2021-22 - Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter","severity":"low","exploited":false,"published_at":"2021-04-15T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-29431-ssrf-in-sydent-due-to-missing-validation-of-hostnames"},{"cve":"CVE-2021-29430","cvss":3.1,"epss":0.0183,"slug":"cve-2021-29430-sydent-vulnerable-to-denial-of-service-attack-via-memory","title":"PYSEC-2021-21 - Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. A malicious user cou","severity":"low","exploited":false,"published_at":"2021-04-15T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-29430-sydent-vulnerable-to-denial-of-service-attack-via-memory"},{"cve":"CVE-2021-29433","cvss":3.1,"epss":0.0093,"slug":"cve-2021-29433-sydent-dos-via-resource-exhaustion-due-to-improper-input","title":"PYSEC-2021-24 - ### Impact Missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of","severity":"low","exploited":false,"published_at":"2021-04-15T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-29433-sydent-dos-via-resource-exhaustion-due-to-improper-input"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"matrix-sydent (PyPI)","slug":"matrix-sydent","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"url":"https://junglewise.ai/threats/technologies/matrix-sydent"},"most_severe":[{"cve":"CVE-2021-29430","cvss":3.1,"epss":0.0183,"slug":"cve-2021-29430-sydent-vulnerable-to-denial-of-service-attack-via-memory","title":"PYSEC-2021-21 - Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. A malicious user cou","severity":"low","exploited":false,"published_at":"2021-04-15T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-29430-sydent-vulnerable-to-denial-of-service-attack-via-memory"},{"cve":"CVE-2021-29431","cvss":3.1,"epss":0.0119,"slug":"cve-2021-29431-ssrf-in-sydent-due-to-missing-validation-of-hostnames","title":"PYSEC-2021-22 - Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due to lack of parameter","severity":"low","exploited":false,"published_at":"2021-04-15T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-29431-ssrf-in-sydent-due-to-missing-validation-of-hostnames"},{"cve":"CVE-2021-29432","cvss":3.1,"epss":0.0093,"slug":"cve-2021-29432-malicious-users-could-abuse-sydent-to-control-the-content-of","title":"PYSEC-2021-23 - Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the Sydent email address","severity":"low","exploited":false,"published_at":"2021-04-15T21:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-29432-malicious-users-could-abuse-sydent-to-control-the-content-of"},{"cve":"CVE-2021-29433","cvss":3.1,"epss":0.0093,"slug":"cve-2021-29433-sydent-dos-via-resource-exhaustion-due-to-improper-input","title":"PYSEC-2021-24 - ### Impact Missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of","severity":"low","exploited":false,"published_at":"2021-04-15T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-29433-sydent-dos-via-resource-exhaustion-due-to-improper-input"},{"cve":"CVE-2023-38686","cvss":3.1,"epss":0.0027,"slug":"cve-2023-38686-sydent-does-not-verify-email-server-certificates","title":"PYSEC-2023-139 - Sydent is an identity server for the Matrix communications protocol. Prior to version 2.5.6, if configured to send emails using TLS, Sydent","severity":"low","exploited":false,"published_at":"2023-08-04T16:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-38686-sydent-does-not-verify-email-server-certificates"},{"cve":"CVE-2019-11340","cvss":3,"epss":0.0188,"slug":"cve-2019-11340-matrix-sydent-mishandles-emails","title":"PYSEC-2026-843 - Matrix Sydent mishandles emails","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:28.015702+00:00","url":"https://junglewise.ai/threats/cve-2019-11340-matrix-sydent-mishandles-emails"},{"cve":"CVE-2019-11842","cvss":3,"epss":0.018,"slug":"cve-2019-11842-matrix-sydent-and-matrix-synapse-use-cryptographically-weak-prng","title":"PYSEC-2026-2620 - matrix-sydent and matrix-synapse Use Cryptographically Weak PRNG","severity":"low","exploited":false,"published_at":"2026-07-09T16:49:47.132995+00:00","url":"https://junglewise.ai/threats/cve-2019-11842-matrix-sydent-and-matrix-synapse-use-cryptographically-weak-prng"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}