Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Lemur — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in Lemur, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the Lemur product, specifically focusing on its implementation as a configuration management tool and related infrastructure management weaknesses. The collection encompasses various defect types, including information disclosure, denial of service, and unauthorized access issues, covering reported incidents from its initial public release through the most recent security disclosures. Users can utilize this resource to track vendor advisories, analyze the prevalence of specific weakness classes, and examine the historical vulnerability profile of the Lemur software stack. By reviewing these entries, security professionals can identify recurring patterns in code defects and assess the overall security posture of environments utilizing Lemur for certificate management and infrastructure automation. The data presented here serves as a neutral reference for risk assessment, allowing organizations to correlate internal findings with known external vulnerabilities without relying on proprietary threat intelligence feeds. This compilation facilitates a structured review of past security flaws, enabling defenders to implement targeted mitigations and monitor for potential exploit chains that may affect similar architectural designs. The focus remains strictly on documented vulnerabilities and their technical characteristics, providing a clear timeline of security evolution for this specific product category.

Vendor: Netflix

CVE ID Title CVSS Severity Published
CVE-2026-71417 Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it CWE-639 7.3 High 2026-08-18
CVE-2026-71322 Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False CWE-862 4.3 Medium 2026-08-18
CVE-2026-71317 Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority CWE-862 6.5 Medium 2026-08-18
CVE-2026-70666 Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs CWE-918 7.4 High 2026-08-18
CVE-2026-71303 Lemur: Incomplete fix for CVE-2026-55166 -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist CWE-918 7.7 High 2026-08-18
CVE-2026-71307 Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API CWE-862 7.7 High 2026-08-18
CVE-2026-71308 Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates CWE-639 8.1 High 2026-08-18
CVE-2026-70667 Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for CVE-2026-55162) CWE-367 6.3 Medium 2026-08-18
CVE-2026-55164 Lemur: Plaintext password storage in Lemur user-update path CWE-256 4.9 Medium 2026-08-18
CVE-2026-55162 Lemur: Post-authentication SSRF via certificate verification - attacker-controlled CRL and OCSP URLs in uploaded certificates CWE-918 6.3 Medium 2026-08-18
CVE-2026-55166 Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and creator-equality IDOR CWE-285 9.9 Critical 2026-08-18
CVE-2026-55163 Lemur: Privilege escalation via PUT /api/1/roles/<id> — non-admin role members can rewrite role membership CWE-863 6.3 Medium 2026-08-18
CVE-2026-55165 Lemur : JWT verifier trusts attacker-supplied alg from token header — defense-in-depth gap; chain-dependent ATO with secret disclosure CWE-347 4.8 Medium 2026-08-18
CVE-2026-48508 Lemur: Authorization bypass in StrictRolePermission / AuthorityCreatorPermission CWE-863 8.8 High 2026-08-18
CVE-2026-44305 Lemur: LDAP TLS certificate verification globally disabled enables credential interception CWE-295 6.8 Medium 2026-05-12
CVE-2026-44304 Lemur: LDAP Filter Injection enables post-authentication privilege escalation CWE-90 8.1 High 2026-05-12
CVE-2023-30797 Insecure Random Generation in Netflix Lemur CWE-330 7.5 High 2023-04-19

All 17 known CVE vulnerabilities affecting Lemur with full Chinese analysis, references, and POCs where available.