Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 19 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 19 Aug 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stigmem before 0.9.0a11 fails to validate the delivery_address parameter when creating webhook subscriptions, allowing authenticated users to specify internal loopback and private network destinations. Attackers can trigger matching fact-change events to cause the Stigmem server to issue server-side HTTP POST requests to internal services, enabling blind SSRF attacks against localhost and private network endpoints. | |
| Title | Stigmem before 0.9.0a11 SSRF via unvalidated webhook delivery_address | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-19T14:43:14.349Z
Reserved: 2026-08-19T11:38:33.224Z
Link: CVE-2026-76239
Updated: 2026-08-19T14:42:57.342Z
Status : Received
Published: 2026-08-19T14:17:56.157
Modified: 2026-08-19T15:18:11.123
Link: CVE-2026-76239
No data.
OpenCVE Enrichment
No data.