stigmem-node has 14 CVEs on record. Cadence is steady at roughly 8 per quarter. The busiest recent month was August 2026 with 8. The median CVSS is 6.3 (medium), with 3 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-639 (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.3
- Publish → KEV
- —
- Last 90 days
- 8 prev 6
Worst active — by depth score
CVE-2026-76244Criticalstigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled52CVE-2026-76242Criticalstigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step52CVE-2026-76243Criticalstigmem-node: Auth-disabled deployments may grant broad anonymous access outside loopback52CVE-2026-76245Highstigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federation peer-token validation that can cause valid peer tokens to be incorrectly treated as expired41CVE-2026-76241Highstigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment41
stigmem-node vulnerabilities
CVEs affecting stigmem-node, newest first. Open any entry for full detail, references, and exploit status.
14 CVEsRSS
CVE-2026-76239Medium· 6.3stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address
stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address
GHSA-5p3m-vhh6-9236Medium· 6.3stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address
stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address
CVE-2026-76245Highstigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federation peer-token validation that can cause valid peer tokens to be incorrectly treated as expired
stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federation peer-token validation that can cause valid peer tokens to be incorrectly treated as expired. This affects the availability and reliab…
CVE-2026-76236Highstigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism
stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism. issue_tombstone defaulted the tenant to "default" instead of the caller's tenant,…
CVE-2026-76241Highstigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment
stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment. If that setting is carried into an environment where plugin directories are writable by les…
CVE-2026-76244Criticalstigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled
stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. Operators who explicitly disabled mTLS while bindi…
CVE-2026-76242Criticalstigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step
stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step. On nodes that accept federation peer registration over a network where initial reg…
CVE-2026-76240Highstigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting
stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting. In the affected code path the schema value is operator-controlled, but the unsafe pattern could allow SQL injection if a sc…
CVE-2026-76237Highstistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)
stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)
CVE-2026-76238Highstigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)
stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)
GHSA-x26h-xmv8-gxf7Highstigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)
stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA)
GHSA-xhv3-q4xx-349rHighstistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)
stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA)
GHSA-6gqw-jqv7-v88mHighstigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)
stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA)
CVE-2026-76243Criticalstigmem-node: Auth-disabled deployments may grant broad anonymous access outside loopback
stigmem-node: Auth-disabled deployments may grant broad anonymous access outside loopback