PT-2026-78420 · Stigmem · Stigmem

·

CVE-2026-76239

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Stigmem versions prior to 0.9.0a11
Description Authenticated users can perform blind Server-Side Request Forgery (SSRF) attacks by specifying internal loopback or private network destinations in the delivery address parameter during the creation of webhook subscriptions. By triggering matching fact-change events, an attacker can force the server to send HTTP POST requests to internal services and private network endpoints.
Recommendations Update to version 0.9.0a11 or later. Avoid using the delivery address parameter to point to internal or loopback addresses until the update is applied.

Exploit

Fix

RCE

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76239
GHSA-5P3M-VHH6-9236

Affected Products

Stigmem