Insecure Default Configuration in stigmem-node by Eidetic Labs
CVE-2026-76244
9.1CRITICAL
What is CVE-2026-76244?
The stigmem-node product from Eidetic Labs is susceptible to an insecure default configuration vulnerability. This issue arises when federation traffic is allowed to traverse networks without mutual TLS (mTLS) protection, particularly when non-loopback endpoints are enabled. Operators who have explicitly disabled mTLS while binding federation to these non-loopback addresses inadvertently expose sensitive federation traffic to interception, putting their systems at risk of cleartext data exposure and potential man-in-the-middle attacks. It is crucial for users to review their configurations and ensure that mTLS is appropriately enabled to safeguard their data in transit.
Affected Version(s)
stigmem 0 < 0.9.0a2
stigmem 0.9.0a2
