vciy

CVEs we hold for Netflix

Records whose assigning authority named Netflix as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-71417Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking itNetflix lemur
CVE-2026-71322Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = FalseNetflix lemur
CVE-2026-71317Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authorityNetflix lemur
CVE-2026-71308Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificatesNetflix lemur
CVE-2026-71307Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key…Netflix lemur
CVE-2026-71303Lemur: Incomplete fix for CVE-2026-55166 -- ACME authority update endpoint allows non-admin to replace `acme_url` with…Netflix lemur
CVE-2026-70667Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete…Netflix lemur
CVE-2026-70666Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLsNetflix lemur
CVE-2026-55166Lemur: any SSO-authenticated user achieves AWS IAM compromise and permanent PKI key access via ACME acme_url SSRF and…Netflix lemur
CVE-2026-55165Lemur : JWT verifier trusts attacker-supplied alg from token header — defense-in-depth gap…Netflix lemur
CVE-2026-55164Lemur: Plaintext password storage in Lemur user-update pathNetflix lemur
CVE-2026-55163Lemur: Privilege escalation via PUT /api/1/roles/<id> — non-admin role members can rewrite role membershipNetflix lemur
CVE-2026-55162Lemur: Post-authentication SSRF via certificate verification - attacker-controlled CRL and OCSP URLs in uploaded…Netflix lemur
CVE-2026-48508Lemur: Authorization bypass in StrictRolePermission / AuthorityCreatorPermissionNetflix lemur
CVE-2026-44305Lemur: LDAP TLS certificate verification globally disabled enables credential interceptionNetflix lemur
CVE-2026-44304Lemur: LDAP Filter Injection enables post-authentication privilege escalationNetflix lemur
CVE-2024-9301no title heldNetflix E2Nest
CVE-2024-7093Server-Side Template Injection in Dispatch Message TemplatesNetflix Dispatch
CVE-2024-5023Arbitrary File Read Vulnerability in ConsoleMe via Limited Git command RCENetflix ConsoleMe
CVE-2024-4701Path Traversal vulnerability via File Uploads in GenieNetflix Genie
CVE-2023-40171Dispatch writes JWT tokens in error messageNetflix dispatch
CVE-2023-30797Insecure Random Generation in Netflix LemurNetflix Lemur
CVE-2021-28100no title heldn/a Netflix OSS Priam
CVE-2021-28099no title heldn/a Netflix OSS Hollow
CVE-2020-9301no title heldn/a Netflix Spinnaker
CVE-2020-9300no title heldn/a Netflix Dispatch
CVE-2020-9299no title heldn/a Netflix Dispatch
CVE-2020-9298no title heldn/a Netflix Orca Spinnaker
CVE-2020-9297no title heldn/a Netflix Titus
CVE-2020-9296no title heldn/a Netflix Titus
CVE-2019-10028no title heldNetflix Dial Reference Source Code Repo…

31 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.