These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-76245 is a HIGH-severity vulnerability in the stigmem (pip package stigmem-node) version 0.9.0a1. A timestamp-handling mismatch in federation peer-token validation can cause valid peer tokens to be incorrectly treated as expired, affecting the availability and reliability of authenticated federation flows on nodes using federation peer authentication paths. The issue is fixed in 0.9.0a2.
CVE-2026-76244 debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T14:17:56.827Z and has not been modified since then. The NVD entry is currently Deferred. Operators who explicitly disabled mTLS while binding federation to non-loopback addresses expose federation traffic to cleartext interception and man-in-the-middle attacks. This insecure default configuration vulnera [truncated]
The CVE-2026-76243 vulnerability affects stigmem versions before 0.9.0a2, allowing unauthenticated access when authentication is disabled on non-loopback deployments. This critical vulnerability enables attackers to perform read, write, and federation operations with anonymous identity. Organizations should be aware of this vulnerability and take immediate action to remediate it, especially those with non [truncated]
CVE-2026-76242 is a critical vulnerability in stigmem-node 0.9.0a1 that allows an attacker to register a malicious peer and gain access to or tamper with federation traffic. The vulnerability exists because stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step. On nodes that accept federation peer registrat [truncated]
CVE-2026-76240 debrief: stigmem-node 0.9.0a1 has a SQL injection vulnerability due to unsafe schema identifier interpolation. Fixed in 0.9.0a2. The vulnerability allows potential code execution if schema names are derived from untrusted input. Defenders should assess exposure and prioritize remediation, especially in deployments using tenant or user-controlled schema names. The CVE record and NVD entry pr [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T14:17:56.157Z and has not been modified since then. Stigmem before 0.9.0a11 fails to validate the delivery_address parameter when creating webhook subscriptions, allowing authenticated users to specify internal loopback and private network destinations. Attackers can trigger matching fact-change [truncated]
The CVE-2026-76238 record indicates a broken object level authorization vulnerability in stigmem versions before 0.9.0a12. This vulnerability exists in the decay sweep endpoint and allows authenticated attackers with write credentials for one tenant to execute decay operations affecting all tenants. The vulnerability can be exploited by submitting POST requests to the decay sweep endpoint with ttl_seconds [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T14:17:55.840Z and has not been modified since then. The stigmem-node package before version 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulnerability in its quarantine review endpoints. This issue affects multi-tenant deployments that use the stigmem-plugin-multi-ten [truncated]
A cross-tenant broken object level authorization (BOLA) flaw was found in stigmem-node before version 0.9.0a12. The issue affects multi-tenant deployments using the stigmem-plugin-multi-tenant and allows a tenant's deletion to be attributed to the wrong tenant, undermining data isolation and right-to-be-forgotten (RTBF) guarantees. This vulnerability has a high CVSS score of 7.2 and is classified as HIGH [truncated]