{"id":"PYSEC-2026-843","summary":"Matrix Sydent mishandles emails","details":"util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids option is enabled. This occurs because of potentially unwanted behavior in Python, in which an email.utils.parseaddr call on user@bad.example.net@good.example.com returns the user@bad.example.net substring.","aliases":["CVE-2019-11340","GHSA-q9h8-gpw5-c95c"],"modified":"2026-07-07T11:46:05.809734259Z","published":"2026-07-06T08:03:28.015702Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-11340"},{"type":"WEB","url":"https://github.com/matrix-org/sydent/commit/4e1cfff53429c49c87d5c457a18ed435520044fc"},{"type":"WEB","url":"https://github.com/matrix-org/sydent/compare/7c002cd...09278fb"},{"type":"WEB","url":"https://matrix.org/blog/2019/04/18/security-update-sydent-1-0-2"},{"type":"WEB","url":"https://twitter.com/matrixdotorg/status/1118934335963500545"},{"type":"PACKAGE","url":"https://pypi.org/project/matrix-sydent"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q9h8-gpw5-c95c"}],"affected":[{"package":{"name":"matrix-sydent","ecosystem":"PyPI","purl":"pkg:pypi/matrix-sydent"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.2"}]}],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/matrix-sydent/PYSEC-2026-843.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}