Vulnerability Description
stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. Operators who explicitly disabled mTLS while binding federation to non-loopback addresses expose federation traffic to cleartext interception and man-in-the-middle attacks.
Related Weaknesses (CWE)
References
- https://github.com/eidetic-labs/stigmem/security/advisories/GHSA-jmfc-hfjq-pxcp
- https://www.vulncheck.com/advisories/stigmem-node-insecure-federation-transport-
FAQ
What is CVE-2026-76244?
CVE-2026-76244 is a documented vulnerability. stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. Operators who...
How severe is CVE-2026-76244?
CVSS scoring is not yet available for CVE-2026-76244. Check NVD for updates.
Is there a patch for CVE-2026-76244?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.