PT-2026-78425 · Unknown · Stigmem-Node

CVE-2026-76244

·

Published

2026-05-29

·

Updated

2026-08-19

CVSS v4.0

9.1

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions stigmem-node (affected versions not specified)
Description An insecure default configuration allows federation traffic to traverse networks without mTLS (mutual Transport Layer Security, a process where both parties in a communication session authenticate each other) protection when non-loopback endpoints are enabled. Operators who explicitly disable mTLS while binding federation to non-loopback addresses expose federation traffic to cleartext interception and man-in-the-middle attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76244
GHSA-JMFC-HFJQ-PXCP

Affected Products

Stigmem-Node