GHSA-rqm4-4g3h-95wmCritical

stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on...

Published
August 19, 2026
Last Modified
August 19, 2026

🔗 CVE IDs covered (1)

📋 Description

stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read, write, and federation operations with anonymous identity when nodes are exposed outside local development environments.

🔗 References (4)