cbcvebase.

Eidetic-Labs Stigmem vulnerabilities

6 known vulnerabilities affecting eidetic-labs/stigmem.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH3

Vulnerabilities

Page 1 of 1
CVE-2026-76243P2CRITICALCVSS 9.2fixed in 0.9.0a22026-08-19
CVE-2026-76243 [CRITICAL] CWE-285 CVE-2026-76243: stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non- stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read, write, and federation operations with anonymous identity when nodes are exposed outside local development environments.
nvd
CVE-2026-76242P3CRITICALCVSS 9.1fixed in 0.9.0a22026-08-19
CVE-2026-76242 [CRITICAL] CWE-295 CVE-2026-76242: stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separat stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step. On nodes that accept federation peer registration over a network where initial registration can be intercepted or misdirected, an attacker can register a malicious peer and gain access to or tam
nvd
CVE-2026-76244P3CRITICALCVSS 9.1fixed in 0.9.0a22026-08-19
CVE-2026-76244 [CRITICAL] CWE-319 CVE-2026-76244: stigmem-node contains an insecure default configuration vulnerability that allows federation traffic stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. Operators who explicitly disabled mTLS while binding federation to non-loopback addresses expose federation traffic to cleartext interception and man-in-the-middl
nvd
CVE-2026-76240P3HIGHCVSS 7.5fixed in 0.9.0a22026-08-19
CVE-2026-76240 [HIGH] CWE-89 CVE-2026-76240: stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defen stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting. In the affected code path the schema value is operator-controlled, but the unsafe pattern could allow SQL injection if a schema name were derived from tenant, request, or user input. Fixed in 0.9.0a2, which adds identifier quoting and valid
nvd
CVE-2026-76241P3HIGHCVSS 7.3fixed in 0.9.0a22026-08-19
CVE-2026-76241 [HIGH] CWE-494 CVE-2026-76241: stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration f stigmem-node 0.9.0a1 allows plugin signature enforcement to be disabled via a single configuration flag without a second explicit acknowledgment. If that setting is carried into an environment where plugin directories are writable by less-trusted users, unsigned (potentially malicious) plugin code could be loaded and executed, resulting in arbitrary c
nvd
CVE-2026-76245P3HIGHCVSS 7.1fixed in 0.9.0a22026-08-19
CVE-2026-76245 [HIGH] CWE-345 CVE-2026-76245: stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federat stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federation peer-token validation that can cause valid peer tokens to be incorrectly treated as expired. This affects the availability and reliability of authenticated federation flows on nodes using federation peer authentication paths. The issue is fixed in 0
nvd
Eidetic-Labs Stigmem vulnerabilities | cvebase