CVE-2026-21894: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-21894 is an authentication bypass vulnerability in the n8n workflow automation platform's Stripe Trigger node, titled "Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks." The flaw affects n8n versions >= 0.150.0 and < 2.2.2 (npm package). It was disclosed on January 7, 2026 via a GitHub Security Advisory published by n8n maintainer csuermann, and subsequently published to the NVD on January 8, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, n8n Security Advisory).

Technical details

The root cause is classified as CWE-290 (Authentication Bypass by Spoofing). The Stripe Trigger node correctly creates and stores a Stripe webhook signing secret upon registering the webhook endpoint, but the incoming webhook request handler never validated the Stripe-Signature header against that stored secret. As a result, any unauthenticated HTTP client that knows the webhook URL could send a crafted POST request with a matching Stripe event type (e.g., charge.succeeded, customer.subscription.updated) and cause the workflow to execute as if a legitimate Stripe event had been received. The fix, introduced in PR #22764, adds a verifySignature helper that parses the Stripe-Signature header, validates the HMAC-SHA256 signature using the stored secret, and enforces a 300-second timestamp tolerance window to prevent replay attacks (n8n Security Advisory, Patch Commit).

Impact

Successful exploitation allows an unauthenticated attacker to trigger arbitrary n8n workflows that use the Stripe Trigger node by forging payment or subscription events (e.g., faking a successful payment, a subscription upgrade, or a refund). This primarily affects workflow integrity — downstream business logic such as order fulfillment, account provisioning, or subscription management could be manipulated without any legitimate Stripe transaction occurring. Confidentiality impact is low (the attacker may observe workflow execution responses), and there is no direct availability impact. The practical risk is partially mitigated by the high-entropy UUID embedded in the webhook URL, though authenticated n8n users with workflow access can view this ID (n8n Security Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.023% (7th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires knowledge of the webhook URL (which contains a high-entropy UUID), raising the effective attack complexity, though insider threat or information leakage scenarios could expose this URL.

Exploitation steps

  1. Reconnaissance: Identify an n8n instance with an active workflow using the Stripe Trigger node. The webhook URL can be obtained by an authenticated n8n user with workflow access, or potentially through log/error message leakage.
  2. Obtain the webhook URL: The URL follows the pattern https://<n8n-host>/webhook/<UUID> where the UUID is unique per workflow. An insider or compromised n8n account can retrieve this from the workflow editor.
  3. Craft a forged Stripe event payload: Construct a JSON body mimicking a legitimate Stripe event, specifying the desired event type (e.g., {"type": "charge.succeeded", "id": "ch_fake123", ...}).
  4. Send the forged POST request: Use any HTTP client (e.g., curl) to POST the crafted payload to the webhook URL without any Stripe-Signature header — the vulnerable node does not validate it: curl -X POST https://<n8n-host>/webhook/<UUID> -H 'Content-Type: application/json' -d '{"type":"charge.succeeded",...}'.
  5. Trigger workflow execution: The n8n Stripe Trigger node processes the forged event as legitimate, executing downstream workflow actions such as order fulfillment, account upgrades, or notifications (n8n Security Advisory, Patch Commit).

Indicators of compromise

  • Network: Unexpected POST requests to n8n webhook endpoints (/webhook/<UUID>) originating from non-Stripe IP ranges (Stripe's webhook IPs are documented and can be allowlisted); requests lacking a Stripe-Signature header or with a malformed one.
  • Logs: n8n execution logs showing Stripe Trigger workflow executions at unusual times or frequencies not correlated with actual Stripe dashboard events; workflow execution records for payment/subscription events that do not appear in the Stripe dashboard.
  • Application Behavior: Downstream actions (e.g., order creation, subscription changes, email notifications) triggered without corresponding Stripe transaction records; unexpected workflow execution counts in n8n's execution history for Stripe Trigger workflows.

Mitigation and workarounds

Upgrade n8n to version 2.2.2 or later, which adds proper HMAC-SHA256 Stripe-Signature header verification with a 5-minute timestamp tolerance window. If immediate upgrade is not possible, deactivate all workflows using the Stripe Trigger node, or restrict access to those workflows to trusted users only to prevent webhook URL exposure. Additionally, configure a Stripe webhook signing secret in the n8n Stripe API credentials after upgrading, as the fix only enforces verification when a secret is configured. Network-level controls (e.g., allowlisting Stripe's published IP ranges at the firewall) can further reduce exposure (n8n Security Advisory, PR #22764).

Community reactions

The vulnerability was credited to security researchers nkoorty and jjjutla, with geckosecurity listed as the tool used for discovery, and a technical write-up was published by Gecko Security (Gecko Security Blog). A Reddit thread in r/bugbounty discussed the vulnerability, and a blog post on infinitsec.net provided additional coverage. Community reaction has been relatively muted given the moderate severity and absence of active exploitation.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management