Insecure Default Configuration in stigmem-node by Eidetic Labs
CVE-2026-76244

9.1CRITICAL

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-76244?

The stigmem-node product from Eidetic Labs is susceptible to an insecure default configuration vulnerability. This issue arises when federation traffic is allowed to traverse networks without mutual TLS (mTLS) protection, particularly when non-loopback endpoints are enabled. Operators who have explicitly disabled mTLS while binding federation to these non-loopback addresses inadvertently expose sensitive federation traffic to interception, putting their systems at risk of cleartext data exposure and potential man-in-the-middle attacks. It is crucial for users to review their configurations and ensure that mTLS is appropriately enabled to safeguard their data in transit.

Affected Version(s)

stigmem 0 < 0.9.0a2

stigmem 0.9.0a2

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.