Alpine: multiple synapse packages: security update to 1.147.1-r0

critical Tenable Self-Hosted Container Security Plugin ID 437721

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm
charts and Kubernetes distribution. The ESS Community Helm Chart secrets initialization hook (using
matrix-tools container before 0.5.7) is using an insecure Matrix server key generation method, allowing
network attackers to potentially recreate the same key pair, allowing them to impersonate the victim
server. The secret is generated by the secrets initialization hook, in the ESS Community Helm Chart
values, if both initSecrets.enabled is not set to false and synapse.signingKey is not defined. Given a
server key in Matrix authenticates both requests originating from and events constructed on a given
server, this potentially impacts confidentiality, integrity and availability of rooms which have a
vulnerable server present as a member. The confidentiality of past conversations in end-to-end encrypted
rooms is not impacted. The key generation issue was fixed in matrix-tools 0.5.7, released as part of ESS
Community Helm Chart 25.12.1. (CVE-2026-24044)

See Also

https://security.alpinelinux.org/vuln/CVE-2026-24044

Plugin Details

Severity: Critical

ID: 437721

Version: Revision 1.10

Type: Local

Published: 2/13/2026

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.43

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2026-24044

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.2

Threat Score: 7.2

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 2/12/2026

Reference Information

CVE: CVE-2026-24044