stigmem-node
PyPI10 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting stigmem-nodepage 1 of 1
- CVE-2026-76236HIGHCVSS 7.2EG 7.2✓ Fixed in 0.9.0a122026-08-19
vulnerable: 0.9.0a1 ... 0.9.0a9 (11 versions)
stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism. issue_tombstone defaulted the tenant to "default" instead of the caller's tenant, a…
- CVE-2026-76237HIGHCVSS 8.6EG 8.6✓ Fixed in 0.9.0a122026-08-19
vulnerable: 0.9.0a1 ... 0.9.0a9 (11 versions)
stigmem-node before 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulnerability in the quarantine review endpoints. On multi-tenant deployments running the opt-in stigmem-plugin-multi-tenant, the list/count quer…
- CVE-2026-76238HIGHCVSS 7.2EG 7.2✓ Fixed in 0.9.0a122026-08-19
vulnerable: 0.9.0a1 ... 0.9.0a9 (11 versions)
stigmem versions before 0.9.0a12 contain a broken object level authorization vulnerability in the decay sweep endpoint that allows authenticated attackers with write credentials for one tenant to execute decay operations affecting all tena…
- CVE-2026-76239MEDIUMCVSS 6.3EG 6.3✓ Fixed in 0.9.0a112026-08-19
vulnerable: 0.9.0a1 ... 0.9.0a9 (10 versions)
Stigmem before 0.9.0a11 fails to validate the delivery_address parameter when creating webhook subscriptions, allowing authenticated users to specify internal loopback and private network destinations. Attackers can trigger matching fact-c…
- CVE-2026-76240HIGHCVSS 7.5EG 7.5✓ Fixed in 0.9.0a22026-08-19
vulnerable: 0.9.0a1
stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting. In the affected code path the schema value is operator-controlled, but the unsafe pattern could allow SQL injection if a sche…
- CVE-2026-76241HIGHCVSS 7.3EG 7.3✓ Fixed in 0.9.0a22026-08-19
vulnerable: 0.9.0a1
stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment. If that setting is carried into an environment where plugin directories are writable by less-…
- CVE-2026-76242CRITICALCVSS 9.1EG 9.1✓ Fixed in 0.9.0a22026-08-19
vulnerable: 0.9.0a1
stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step. On nodes that accept federation peer registration over a network where initial regis…
- CVE-2026-76243CRITICALCVSS 9.2EG 9.2✓ Fixed in 0.9.0a22026-08-19
vulnerable: 0.9.0a1
stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read, write, and federation operations with anonymous identity when nodes are exposed outside l…
- CVE-2026-76244CRITICALCVSS 9.1EG 9.1✓ Fixed in 0.9.0a22026-08-19
vulnerable: 0.9.0a1
stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. Operators who explicitly disabled mTLS while binding…
- CVE-2026-76245HIGHCVSS 7.1EG 7.1✓ Fixed in 0.9.0a22026-08-19
vulnerable: 0.9.0a1
stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federation peer-token validation that can cause valid peer tokens to be incorrectly treated as expired. This affects the availability and reliabil…
Check whether stigmem-node is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for stigmem-node CVEs against the assets you own.
Start Free Scan →