{"id":"GHSA-9vp8-3hmv-8fgh","summary":"stigmem-node's federation peer registration lacked explicit out-of-band approval","details":"### Impact\nFederation peer registration accepted peer key material during registration without a separate administrator approval step based on an out-of-band fingerprint check. Impacted deployments are nodes that accept federation peer registration across a network where initial registration could be intercepted or misdirected.\n\n### Patches\nPatched in 0.9.0a2. Peer registration now uses a pending approval flow, and peer tokens are not accepted until an administrator approves the peer using the expected fingerprint.\n\n### Workarounds\nBefore upgrading, restrict peer registration endpoints to trusted administrative networks and verify peer public-key fingerprints out of band before allowing federation traffic.\n\n### Upgrade\nUpgrade to the patched release:\n\n```bash\npip install --upgrade --pre stigmem-node\n```\n\nIf developers install through the Stigmem meta-package instead, they should use the matching extra for deployments, for example:\n\n```bash\npip install --upgrade --pre 'stigmem[node]'\n```\n\n### Resources\n- Release: https://github.com/eidetic-labs/stigmem/releases/tag/v0.9.0a2\n- Changelog: https://github.com/eidetic-labs/stigmem/blob/v0.9.0a2/CHANGELOG.md#L14-L35\n- Security policy and posture: https://github.com/eidetic-labs/stigmem/blob/v0.9.0a2/SECURITY.md","aliases":["CVE-2026-76242"],"modified":"2026-08-20T04:04:15.601026750Z","published":"2026-05-29T22:18:19Z","database_specific":{"github_reviewed_at":"2026-05-29T22:18:19Z","nvd_published_at":null,"cwe_ids":["CWE-295","CWE-345"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/eidetic-labs/stigmem/security/advisories/GHSA-9vp8-3hmv-8fgh"},{"type":"PACKAGE","url":"https://github.com/eidetic-labs/stigmem"},{"type":"WEB","url":"https://github.com/eidetic-labs/stigmem/blob/v0.9.0a2/CHANGELOG.md#L14-L35"},{"type":"WEB","url":"https://github.com/eidetic-labs/stigmem/blob/v0.9.0a2/SECURITY.md"},{"type":"WEB","url":"https://github.com/eidetic-labs/stigmem/releases/tag/v0.9.0a2"}],"affected":[{"package":{"name":"stigmem-node","ecosystem":"PyPI","purl":"pkg:pypi/stigmem-node"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.0a2"}]}],"versions":["0.9.0a1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-9vp8-3hmv-8fgh/GHSA-9vp8-3hmv-8fgh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}