{"id":"CVE-2026-76242","aliases":["GHSA-9vp8-3hmv-8fgh"],"url":"https://o3.security/vulnerability/CVE-2026-76242","summary":"stigmem Federation Peer Registration Authentication Bypass","details":"### Impact\nFederation peer registration accepted peer key material during registration without a separate administrator approval step based on an out-of-band fingerprint check. Impacted deployments are nodes that accept federation peer registration across a network where initial registration could be intercepted or misdirected.\n\n### Patches\nPatched in 0.9.0a2. Peer registration now uses a pending approval flow, and peer tokens are not accepted until an administrator approves the peer using the expected fingerprint.\n\n### Workarounds\nBefore upgrading, restrict peer registration endpoints to trusted administrative networks and verify peer public-key fingerprints out of band before allowing federation traffic.\n\n### Upgrade\nUpgrade to the patched release:\n\n```bash\npip install --upgrade --pre stigmem-node\n```\n\nIf developers install through the Stigmem meta-package instead, they should use the matching extra for deployments, for example:\n\n```bash\npip install --upgrade --pre 'stigmem[node]'\n```\n\n### Resources\n- Release: https://github.com/eidetic-labs/stigmem/releases/tag/v0.9.0a2\n- Changelog: https://github.com/eidetic-labs/stigmem/blob/v0.9.0a2/CHANGELOG.md#L14-L35\n- Security policy and posture: https://github.com/eidetic-labs/stigmem/blob/v0.9.0a2/SECURITY.md","published":"2026-08-19T14:02:19.435Z","modified":"2026-09-13T03:30:52.223069648Z","cvss":null,"epss":{"score":0.00267,"percentile":0.18361,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"stigmem-node","fixedVersion":"0.9.0a2"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76242.json"},{"type":"ADVISORY","url":"https://github.com/eidetic-labs/stigmem/security/advisories/GHSA-9vp8-3hmv-8fgh"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76242"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/stigmem-federation-peer-registration-authentication-bypass"},{"type":"PACKAGE","url":"https://github.com/eidetic-labs/stigmem"},{"type":"WEB","url":"https://github.com/eidetic-labs/stigmem/blob/v0.9.0a2/CHANGELOG.md#L14-L35"},{"type":"WEB","url":"https://github.com/eidetic-labs/stigmem/blob/v0.9.0a2/SECURITY.md"},{"type":"WEB","url":"https://github.com/eidetic-labs/stigmem/releases/tag/v0.9.0a2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-13T03:30:52.223069648Z"}}