Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. stigmem-node
  4. ›
  5. GHSA-jmfc-hfjq-pxcp

GHSA-jmfc-hfjq-pxcp: stigmem-node's federation insecure transport settings may allow non-loopback cleartext federation

May 29, 2026

Stigmem nodes with federation enabled could be configured to run without mTLS outside loopback-only local development. In affected deployments, federation traffic may traverse the network without the intended transport protection. Impacted users are operators who enabled federation and explicitly disabled mTLS while binding the node to a non-loopback URL.

References

  • github.com/advisories/GHSA-jmfc-hfjq-pxcp
  • github.com/eidetic-labs/stigmem/security/advisories/GHSA-jmfc-hfjq-pxcp

Code Behaviors & Features

Detect and mitigate GHSA-jmfc-hfjq-pxcp with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.9.0-a.2

Fixed versions

  • 0.9.0-a.2

Solution

Upgrade to version 0.9.0-a.2 or above.

Impact 9.1 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-319: Cleartext Transmission of Sensitive Information
  • CWE-489: Active Debug Code

Source file

pypi/stigmem-node/GHSA-jmfc-hfjq-pxcp.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 23 Jun 2026 12:24:45 +0000.