CVE-2026-76239

Stigmem before 0.9.0a11 fails to validate the delivery_address parameter when creating webhook subscriptions, allowing authenticated users to specify internal loopback and private network destinations. Attackers can trigger matching fact-change events to cause the Stigmem server to issue server-side HTTP POST requests to internal services, enabling blind SSRF attacks against localhost and private network endpoints.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-19 14:17

Updated : 2026-08-21 12:16


NVD link : CVE-2026-76239

Mitre link : CVE-2026-76239

CVE.ORG link : CVE-2026-76239


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)