Known Vulnerabilities for Lemur by Netflix
Listed below are 2 of the newest known vulnerabilities associated with "Lemur" by "Netflix".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-71417 json | Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a non-read-only user to creat... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-71322 json | Lemur manages TLS certificate creation. Prior to 1.9.3, CertificateExport placed its CertificatePermission ownership check in... | Not Provided | 2026-08-18 | 2026-08-19 |
| CVE-2026-71317 json | Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require AuthorityPerm... | Not Provided | 2026-08-18 | 2026-08-19 |
| CVE-2026-71308 json | Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replac... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-71307 json | Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only on a... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-71303 json | Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_acme_url enforced ACME_DIRECTORY_HOST_ALLOWLIST when an aut... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-70667 json | Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revocation_url in lemur/certificates/verify.py checked the ... | Not Provided | 2026-08-18 | 2026-08-19 |
| CVE-2026-70666 json | Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_url through PUT /api/1/aut... | Not Provided | 2026-08-18 | 2026-08-19 |
| CVE-2026-55166 json | Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url withou... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-55165 json | Lemur manages TLS certificate creation. Prior to 1.9.2, the JWT verifier in lemur/auth/service.py:130-137 used fetch_token_he... | Not Provided | 2026-08-18 | 2026-08-18 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Netflix | Lemur | 0.5 | |||
| Application | Netflix | Lemur | 0.4 | |||
| Application | Netflix | Lemur | 0.3.0 | |||
| Application | Netflix | Lemur | 0.2.2 | |||
| Application | Netflix | Lemur | 0.2.1 | |||
| Application | Netflix | Lemur | 0.2.0 | |||
| Application | Netflix | Lemur | 0.1.5 | |||
| Application | Netflix | Lemur | 0.1.4 |