Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Netflix — Vulnerabilities & Security Advisories 23

Browse all 23 CVE security advisories affecting Netflix. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Netflix operates as a streaming entertainment platform delivering video content on-demand to global subscribers. Historically, the service has faced vulnerabilities including remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from web applications and APIs. While no major public security incidents have been widely reported, the platform maintains robust security measures to protect user data and content. With 7 CVEs currently on record, Netflix continues to address security proactively, focusing on mitigating risks across its digital infrastructure to maintain service integrity and user trust in its content delivery ecosystem.

CVE ID Title CVSS Severity Published
CVE-2026-71417 Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it — lemur CWE-639 7.3 High 2026-08-18
CVE-2026-71322 Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False — lemur CWE-862 4.3 Medium 2026-08-18
CVE-2026-71317 Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority — lemur CWE-862 6.5 Medium 2026-08-18
CVE-2026-70666 Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs — lemur CWE-918 7.4 High 2026-08-18
CVE-2026-71303 Lemur: Incomplete fix for CVE-2026-55166 -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist — lemur CWE-918 7.7 High 2026-08-18
CVE-2026-71307 Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API — lemur CWE-862 7.7 High 2026-08-18
CVE-2026-71308 Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates — lemur CWE-639 8.1 High 2026-08-18
CVE-2026-70667 Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for CVE-2026-55162) — lemur CWE-367 6.3 Medium 2026-08-18
CVE-2026-55164 Lemur: Plaintext password storage in Lemur user-update path — lemur CWE-256 4.9 Medium 2026-08-18
CVE-2026-55162 Lemur: Post-authentication SSRF via certificate verification - attacker-controlled CRL and OCSP URLs in uploaded certificates — lemur CWE-918 6.3 Medium 2026-08-18
CVE-2026-55166 Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and creator-equality IDOR — lemur CWE-285 9.9 Critical 2026-08-18
CVE-2026-55163 Lemur: Privilege escalation via PUT /api/1/roles/<id> — non-admin role members can rewrite role membership — lemur CWE-863 6.3 Medium 2026-08-18
CVE-2026-55165 Lemur : JWT verifier trusts attacker-supplied alg from token header — defense-in-depth gap; chain-dependent ATO with secret disclosure — lemur CWE-347 4.8 Medium 2026-08-18
CVE-2026-48508 Lemur: Authorization bypass in StrictRolePermission / AuthorityCreatorPermission — lemur CWE-863 8.8 High 2026-08-18
CVE-2026-44305 Lemur: LDAP TLS certificate verification globally disabled enables credential interception — lemur CWE-295 6.8 Medium 2026-05-12
CVE-2026-44304 Lemur: LDAP Filter Injection enables post-authentication privilege escalation — lemur CWE-90 8.1 High 2026-05-12
CVE-2024-9301 Netflix e2nest 安全漏洞 — E2Nest CWE-22 6.5AI Medium AI 2024-09-27
CVE-2024-7093 Server-Side Template Injection in Dispatch Message Templates — Dispatch CWE-94 8.8AI High AI 2024-08-01
CVE-2024-5023 Arbitrary File Read Vulnerability in ConsoleMe via Limited Git command RCE — ConsoleMe CWE-77 9.8AI Critical AI 2024-05-16
CVE-2024-4701 Path Traversal vulnerability via File Uploads in Genie — Genie CWE-22 9.9 Critical 2024-05-10
CVE-2023-40171 Dispatch writes JWT tokens in error message — dispatch CWE-209 9.1 Critical 2023-08-17
CVE-2023-30797 Insecure Random Generation in Netflix Lemur — Lemur CWE-330 7.5 High 2023-04-19
CVE-2019-10028 Netflix Dial Reference 输入验证错误漏洞 — Dial Reference Source Code Repo (https://github.com/Netflix/dial-reference) 7.5 - 2019-06-21

This page lists every published CVE security advisory associated with Netflix. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.