VulnSea

stigmem-node vulnerabilities

CVEs whose affected-version data names the stigmem-node package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

14 CVEsRSS

CVE-2026-76239Medium· 6.3
1mo ago

stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address

stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address

Sunlitstigmem-node · stigmem-nodeEPSS 0.27%via OSV
GHSA-5p3m-vhh6-9236Medium· 6.3
1mo ago

stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address

stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address

Sunlitstigmem-node · stigmem-nodevia GHSA
CVE-2026-76245High
1mo ago

stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federation peer-token validation that can cause valid peer tokens to be incorrectly treated as expired

stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federation peer-token validation that can cause valid peer tokens to be incorrectly treated as expired. This affects the availability and reliab…

Twilightstigmem-node · stigmem-nodeEPSS 0.18%via NVD
CVE-2026-76236High
1mo ago

stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism

stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism. issue_tombstone defaulted the tenant to "default" instead of the caller's tenant,…

Twilightstigmem-node · stigmem-nodeEPSS 0.27%via NVD
CVE-2026-76241High
1mo ago

stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment

stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment. If that setting is carried into an environment where plugin directories are writable by les…

Twilightstigmem-node · stigmem-nodeEPSS 0.09%via NVD
CVE-2026-76244Critical
1mo ago

stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled

stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. Operators who explicitly disabled mTLS while bindi…

Midnightstigmem-node · stigmem-nodeEPSS 0.22%via NVD
CVE-2026-76242Critical
1mo ago

stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step

stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step. On nodes that accept federation peer registration over a network where initial reg…

Midnightstigmem-node · stigmem-nodeEPSS 0.27%via NVD
CVE-2026-76240High
1mo ago

stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting

stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting. In the affected code path the schema value is operator-controlled, but the unsafe pattern could allow SQL injection if a sc…

Twilightstigmem-node · stigmem-nodeEPSS 0.28%via NVD
CVE-2026-76237High
3mo ago

stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)

stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)

Twilightstigmem-node · stigmem-nodeEPSS 0.29%via OSV
CVE-2026-76238High
3mo ago

stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)

stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)

Twilightstigmem-node · stigmem-nodeEPSS 0.27%via OSV
GHSA-x26h-xmv8-gxf7High
3mo ago

stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)

stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)

Twilightstigmem-node · stigmem-nodevia GHSA
GHSA-xhv3-q4xx-349rHigh
3mo ago

stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)

stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)

Twilightstigmem-node · stigmem-nodevia GHSA
GHSA-6gqw-jqv7-v88mHigh
3mo ago

stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)

stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)

Twilightstigmem-node · stigmem-nodevia GHSA
CVE-2026-76243Critical
3mo ago

stigmem-node: Auth-disabled deployments may grant broad anonymous access outside loopback

stigmem-node: Auth-disabled deployments may grant broad anonymous access outside loopback

Midnightstigmem-node · stigmem-nodeEPSS 0.40%via OSV
stigmem-node vulnerabilities (CVEs) · VulnSea