Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-5p3m-vhh6-9236
  • PyPI/stigmem-node
stigmem-node has blind SSRF via unvalidated webhook subscription delivery_address 20 Aug
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-6gqw-jqv7-v88m
  • PyPI/stigmem-node
stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA) 19 Jun
  • Fix available
  • Severity - 7.2 (High)
GHSA-xhv3-q4xx-349r
  • PyPI/stigmem-node
stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA) 19 Jun
  • Fix available
  • Severity - 8.6 (High)
GHSA-x26h-xmv8-gxf7
  • PyPI/stigmem-node
stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA) 19 Jun
  • Fix available
  • Severity - 7.2 (High)
GHSA-9vp8-3hmv-8fgh
  • PyPI/stigmem-node
stigmem-node's federation peer registration lacked explicit out-of-band approval 29 May
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-w7pm-9g55-mxfm
  • PyPI/stigmem-node
stigmem-node's unsigned plugin override could be enabled without a second explicit acknowledgment 29 May
  • Fix available
  • Severity - 7.3 (High)
GHSA-jmfc-hfjq-pxcp
  • PyPI/stigmem-node
stigmem-node's federation insecure transport settings may allow non-loopback cleartext federation 29 May
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-9pc9-4crj-mhpj
  • PyPI/stigmem-node
stigmem-node's Postgres schema identifier handling required defensive quoting 29 May
  • Fix available
  • Severity - 7.5 (High)
GHSA-xh5j-xjfq-qvvx
  • PyPI/stigmem-node
stigmem-node's federation peer token timestamp validation may reject valid peer tokens 29 May
  • Fix available
  • Severity - 7.1 (High)
GHSA-fp6w-8wpg-74g5
  • PyPI/stigmem-node
stigmem-node: Auth-disabled deployments may grant broad anonymous access outside loopback 29 May
  • Fix available
  • Severity - 9.2 (Critical)