lemur
PyPI10 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting lemurpage 1 of 1
- CVE-2015-7764HIGHCVSS 7.5EG 7.5✓ Fixed in 0.2.12017-08-09
Lemur 0.1.4 does not use sufficient entropy in its IV when encrypting AES in CBC mode.
- CVE-2023-30797HIGHCVSS 7.5EG 7.5✓ Fixed in 1.3.22023-04-19
vulnerable: 0.11.0 ... 1.3.1 (9 versions)
Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the credentials and gain access to resources managed by Lemur.
- CVE-2026-44304HIGHCVSS 8.1EG 8.1✓ Fixed in 1.9.02026-05-12
vulnerable: 0.11.0 ... 1.8.2 (17 versions)
Lemur manages TLS certificate creation. Prior to 1.9.0, Lemur's LDAP authentication module (lemur/auth/ldap.py) constructs LDAP search filters using unsanitized user input via Python string interpolation. An authenticated LDAP user can inj…
- CVE-2026-44305MEDIUMCVSS 6.8EG 6.8✓ Fixed in 1.9.02026-05-12
vulnerable: 0.11.0 ... 1.8.2 (17 versions)
Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled (LDAP_USE_TLS = True), Lemur's LDAP authentication module unconditionally disables TLS certificate verification at the global ldap module level. This allows a…
- CVE-2026-48508HIGHCVSS 8.8EG 8.8✓ Fixed in 1.9.12026-06-25
vulnerable: 0.11.0 ... 1.9.0 (18 versions)
Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermission ## Summary `StrictRolePermission` and `AuthorityCreatorPermission` in `lemur/auth/permissions.py` call `flask_principal.Permission.__init__()` with ze…
- CVE-2026-55162MEDIUMCVSS 6.3EG 6.3✓ Fixed in 1.9.22026-06-25
vulnerable: 0.11.0 ... 1.9.1 (19 versions)
Lemur: Crafted CRL/OCSP URLs in uploaded certificates lead to post-authentication SSRF ## Summary When verifying an uploaded certificate, `lemur/certificates/verify.py` extracts the CRL Distribution Point URL and the OCSP responder URL …
- CVE-2026-55163MEDIUMCVSS 6.3EG 6.3✓ Fixed in 1.9.22026-06-25
vulnerable: 0.11.0 ... 1.9.1 (19 versions)
Lemur Privilege Escalation: Non-admin role members can rewrite role membership via PUT /api/1/roles/<id> ## Summary The `PUT /api/1/roles/<id>` handler in `lemur/roles/views.py` gates only on `RoleMemberPermission(role_id).can()`, which…
- CVE-2026-55164MEDIUMCVSS 4.9EG 4.9✓ Fixed in 1.9.22026-06-25
vulnerable: 0.11.0 ... 1.9.1 (19 versions)
Lemur user-update path stores plaintext passwords ## Summary `lemur.users.service.update()` writes a user's new password as plaintext to the `users.password` column. The `User` model wires bcrypt hashing to SQLAlchemy's `before_insert` e…
- CVE-2026-55165MEDIUMCVSS 4.8EG 4.8✓ Fixed in 1.9.22026-06-25
vulnerable: 0.11.0 ... 1.9.1 (19 versions)
Lemur: JWT verifier honors attacker-supplied alg, enabling ATO <!-- obsidian --><h1 data-heading="Lemur 1.9.0: JWT verifier trusts attacker-supplied alg from token header — defense-in-depth gap; chain-dependent ATO with secret disclosu…
- CVE-2026-55166CRITICALCVSS 9.9EG 9.9✓ Fixed in 1.9.22026-06-25
vulnerable: 0.11.0 ... 1.9.1 (19 versions)
Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise <!-- obsidian --><h1 data-heading="Lemur 1.9.0: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and creator…
Check whether lemur is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for lemur CVEs against the assets you own.
Start Free Scan →