TLS Management Vulnerability in Lemur by Netflix
CVE-2026-71417
7.3HIGH
What is CVE-2026-71417?
Lemur, a tool for managing TLS certificates, had a vulnerability that allowed non-read-only users to create duplicate entries without appropriate permissions. This occurred due to improper validation during the certificate upload process, enabling attackers to bypass checks preventing the revocation of valid certificates. Consequently, an attacker could revoke legitimate, managed certificates, risking a denial of service across affected systems. The issue was addressed in version 1.9.3, which includes stricter checks for duplicate authority IDs and serial numbers during uploads and revocation processes.
Affected Version(s)
lemur < 1.9.3
