CVEs we hold for Netflix
Records whose assigning authority named Netflix as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-71417Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking itNetflix lemur
CVE-2026-71322Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = FalseNetflix lemur
CVE-2026-71317Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authorityNetflix lemur
CVE-2026-71308Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificatesNetflix lemur
CVE-2026-71307Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key…Netflix lemur
CVE-2026-71303Lemur: Incomplete fix for CVE-2026-55166 -- ACME authority update endpoint allows non-admin to replace `acme_url` with…Netflix lemur
CVE-2026-70667Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete…Netflix lemur
CVE-2026-70666Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLsNetflix lemur
CVE-2026-55166Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and…Netflix lemur
CVE-2026-55165Lemur : JWT verifier trusts attacker-supplied alg from token header — defense-in-depth gap…Netflix lemur
CVE-2026-55163Lemur: Privilege escalation via PUT /api/1/roles/<id> — non-admin role members can rewrite role membershipNetflix lemur
CVE-2026-55162Lemur: Post-authentication SSRF via certificate verification - attacker-controlled CRL and OCSP URLs in uploaded…Netflix lemur
CVE-2026-48508Lemur: Authorization bypass in StrictRolePermission / AuthorityCreatorPermissionNetflix lemur
CVE-2026-44305Lemur: LDAP TLS certificate verification globally disabled enables credential interceptionNetflix lemur
CVE-2026-44304Lemur: LDAP Filter Injection enables post-authentication privilege escalationNetflix lemur
CVE-2024-5023Arbitrary File Read Vulnerability in ConsoleMe via Limited Git command RCENetflix ConsoleMe
31 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.