GHSA-5wrh-4jwv-5w78

    Dashboard / Vulnerabilities / GHSA-5wrh-4jwv-5w78

    GHSA-5wrh-4jwv-5w78

    Published: 13 Apr 2021Last Modified: 8 Jul 2026

    Summary: Open redirect via transitional IPv6 addresses on dual-stack networks

    Details: ### Impact Requests to user provided domains were not restricted to external IP addresses when transitional IPv6 addresses were used. Outbound requests to federation, identity servers, when calculating the key validity for third-party invite events, sending push notifications, and generating URL previews are affected. This could cause Synapse to make requests to internal infrastructure on dual-stack networks. ### Patches This issue is fixed by #9240. ### Workarounds Outbound requests to the following address ranges can be blocked by a firewall, if unused for internal communication between systems: * `::ffff/80` * `::0000/80` (note that this IP range is considered deprecated by the IETF) * `2002::/16` (note that this IP range is considered deprecated by the IETF) ### References * [RFC3056](https://tools.ietf.org/html/rfc3056) * [RFC4291](https://tools.ietf.org/html/rfc4291)

    Affected packages

    Package

    Name: matrix-synapse

    Purl: pkg:pypi/matrix-synapse

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.28.0rc1

    Affected versions

    0.33.5
    0.33.5.1
    0.33.6
    0.33.6rc1
    0.33.7
    0.33.7rc1
    0.33.7rc2
    0.33.8
    0.33.8rc2
    0.33.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-5wrh-4jwv-5w78 | CVE-DB