« Volver al listado

Stigmem

Stigmem-node: vulnerabilidades y CVE

Stigmem-node tiene 6 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE6
Últimos 12 meses6
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-76245Alta (7.1)0.24%—19 ago 2026
stigmem (pip package stigmem-node) version 0.9.0a1 contains a timestamp-handling mismatch in federation peer-token validation that can cause valid peer tokens to be incorrectly treated as expired. This affects the…
CVE-2026-76244Crítica (9.1)0.27%—19 ago 2026
stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. Operators who explicitly…
CVE-2026-76242Crítica (9.1)0.35%—19 ago 2026
stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step. On nodes that accept federation peer registration over a network…
CVE-2026-76240Alta (7.5)0.38%—19 ago 2026
stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting. In the affected code path the schema value is operator-controlled, but the unsafe pattern could allow SQL…
CVE-2026-76237Alta (8.6)0.36%—19 ago 2026
stigmem-node before 0.9.0a12 contains a broken object level authorization (cross-tenant BOLA) vulnerability in the quarantine review endpoints. On multi-tenant deployments running the opt-in stigmem-plugin-multi-tenant,…
CVE-2026-76236Alta (7.2)0.36%—19 ago 2026
stigmem-node before 0.9.0a12 contains a cross-tenant broken object level authorization (BOLA) flaw in the RTBF (right-to-be-forgotten) tombstone mechanism. issue_tombstone defaulted the tenant to "default" instead of…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services4
  2. T1005 Data from Local System3
  3. T1557 Adversary-in-the-Middle2
  4. T1190 Exploit Public-Facing Application1
  5. T1195.002 Compromise Software Supply Chain1
  6. T1578.003 Delete Cloud Instance1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Stigmem