Stigmem before 0.9.0a11 fails to validate the delivery_address parameter when creating webhook subscriptions, allowing authenticated users to specify internal loopback and private network destinations. Attackers can trigger matching fact-change events to cause the Stigmem server to issue server-side HTTP POST requests to internal services, enabling blind SSRF attacks against localhost and private network endpoints.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-19 14:17
Updated : 2026-08-21 12:16
NVD link : CVE-2026-76239
Mitre link : CVE-2026-76239
CVE.ORG link : CVE-2026-76239
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)
