CVE-2021-21273
Python vulnerability analysis and mitigation

Overview

CVE-2021-21273 is a security vulnerability affecting Matrix Synapse, a Matrix reference homeserver written in Python. The vulnerability was discovered and disclosed in early 2021, where requests to user-provided domains were not properly restricted to external IP addresses when calculating key validity for third-party invite events and sending push notifications. This could potentially allow Synapse to make requests to internal infrastructure (GitHub Advisory).

Technical details

The vulnerability stems from insufficient IP address restrictions when handling certain types of requests. Specifically, the issue affected requests related to key validity calculations for third-party invite events and push notification delivery. While the type of request was not controlled by the user, limited modification of request bodies was possible (GitHub Advisory). The vulnerability was assigned a Low severity rating.

Impact

The main impact of this vulnerability was that it could allow Synapse to make unauthorized requests to internal infrastructure through user-provided domains. This could potentially expose internal services or systems to unauthorized access or probing (GitHub Advisory).

Exploitability

The vulnerability required the ability to trigger third-party invite events or push notifications. While the type of request was not directly controllable by an attacker, they could perform limited modifications to request bodies (GitHub Advisory).

Mitigation and workarounds

The issue was resolved in Synapse version 1.25.0. Server administrators were advised to remove the deprecated federation_ip_range_blacklist from their settings after upgrading, which would result in Synapse using improved default IP address restrictions. Alternative configuration options ip_range_blacklist and ip_range_whitelist were provided for more specific control. As a temporary workaround, requests to internal IP addresses could be blocked at the system or network level (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61539CRITICAL10
  • Python logoPython
  • xinference
NoYesAug 21, 2026
CVE-2026-49360HIGH7.8
  • Python logoPython
  • recce
NoYesAug 21, 2026
CVE-2026-68508HIGH7.8
  • Python logoPython
  • hydra-core
NoYesAug 21, 2026
CVE-2026-54457HIGH7.7
  • Python logoPython
  • tensorzero
NoYesAug 21, 2026
CVE-2026-43980MEDIUM6.3
  • Python logoPython
  • malla
NoNoAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management