Stigmem · Stigmem · CVE-2026-76239
**Name of the Vulnerable Software and Affected Versions**
Stigmem versions prior to 0.9.0a11
**Description**
Authenticated users can perform blind Server-Side Request Forgery (SSRF) attacks by specifying internal loopback or private network destinations in the `delivery address` parameter during the creation of webhook subscriptions. By triggering matching fact-change events, an attacker can force the server to send HTTP POST requests to internal services and private network endpoints.
**Recommendations**
Update to version 0.9.0a11 or later.
Avoid using the `delivery address` parameter to point to internal or loopback addresses until the update is applied.