Impact
stigmem‑node contains a default configuration that allows federation traffic to be sent across networks without mutual TLS when non‑loopback endpoints are enabled. This insecure transport exposes all federation packets to eavesdropping and tampering, permitting attackers to intercept, read, or modify messages. The weakness is classified as CWE‑319 – insecure communication, resulting in loss of confidentiality and integrity of data exchanged via federation services.
Affected Systems
The affected product is stigmem from eidetic‑labs. No specific version information is disclosed in the advisory; the issue applies to any instance where federation is bound to non‑loopback addresses and mutual TLS is explicitly disabled.
Risk and Exploitability
The vulnerability has a CVSS score of 9.1, indicating a critical condition. EPSS is not available and the flaw is not listed in the CISA KEV catalog. Attackers can exploit this by simply observing network traffic between nodes that have exposed non‑loopback federation endpoints without encryption. The exploit requires no special privileges and can be performed remotely over the network, resulting in a substantial risk for any environment that relies on stigmem federation for inter‑component communication.
OpenCVE Enrichment