CVE-2026-70666: CWE-918: Server-Side Request Forgery (SSRF) in Netflix lemur
A Server-Side Request Forgery (SSRF) vulnerability exists in Netflix Lemur prior to version 1.9.3. An authority-role member could update the acme_url without revalidation, allowing redirection of ACME client requests to attacker-controlled servers. This flaw enables the Lemur client to follow URLs from malicious ACME servers, potentially sending signed requests to internal or cloud metadata endpoints. The vulnerability requires authority-level access but not global administrator privileges. The issue is fixed in Lemur version 1.9.3 by enforcing host validation during the ACME flow.
AI Analysis
Technical Summary
Netflix Lemur versions before 1.9.3 contain a SSRF vulnerability (CWE-918) where an attacker with authority-role privileges can update the acme_url via the PUT /api/1/authorities/ endpoint without revalidation. This allows directing the Lemur ClientV2 to an attacker-controlled ACME server. Since the ACME directory and order responses include URLs (newNonce, newOrder, authorizations, finalize) chosen by the attacker, the client follows these URLs without verifying that their hosts match the configured directory host. This behavior enables the attacker to cause the client to send JWS-signed requests to internal services or cloud metadata endpoints. The vulnerability does not require global admin rights but does require an ACME authority and authorized user. The fix in version 1.9.3 revalidates updates and introduces a pinned client network to restrict allowed hosts in the ACME flow.
Potential Impact
An attacker with authority-role access can exploit this SSRF vulnerability to make the Lemur client send signed requests to internal or cloud metadata endpoints, potentially leading to unauthorized access or information disclosure. The vulnerability impacts confidentiality, integrity, and availability as indicated by the CVSS vector. However, exploitation requires specific privileges (authority role) and does not require global administrator rights.
Mitigation Recommendations
Upgrade Lemur to version 1.9.3 or later, where the vulnerability is fixed by revalidating acme_url updates and enforcing a single allowed host for the ACME flow. No additional mitigation is required if the system is updated to this version.
CVE-2026-70666: CWE-918: Server-Side Request Forgery (SSRF) in Netflix lemur
Description
A Server-Side Request Forgery (SSRF) vulnerability exists in Netflix Lemur prior to version 1.9.3. An authority-role member could update the acme_url without revalidation, allowing redirection of ACME client requests to attacker-controlled servers. This flaw enables the Lemur client to follow URLs from malicious ACME servers, potentially sending signed requests to internal or cloud metadata endpoints. The vulnerability requires authority-level access but not global administrator privileges. The issue is fixed in Lemur version 1.9.3 by enforcing host validation during the ACME flow.
CVSS v3.1
Score 7.4high
Affected software
Netflix
lemur
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Netflix Lemur versions before 1.9.3 contain a SSRF vulnerability (CWE-918) where an attacker with authority-role privileges can update the acme_url via the PUT /api/1/authorities/ endpoint without revalidation. This allows directing the Lemur ClientV2 to an attacker-controlled ACME server. Since the ACME directory and order responses include URLs (newNonce, newOrder, authorizations, finalize) chosen by the attacker, the client follows these URLs without verifying that their hosts match the configured directory host. This behavior enables the attacker to cause the client to send JWS-signed requests to internal services or cloud metadata endpoints. The vulnerability does not require global admin rights but does require an ACME authority and authorized user. The fix in version 1.9.3 revalidates updates and introduces a pinned client network to restrict allowed hosts in the ACME flow.
Potential Impact
An attacker with authority-role access can exploit this SSRF vulnerability to make the Lemur client send signed requests to internal or cloud metadata endpoints, potentially leading to unauthorized access or information disclosure. The vulnerability impacts confidentiality, integrity, and availability as indicated by the CVSS vector. However, exploitation requires specific privileges (authority role) and does not require global administrator rights.
Mitigation Recommendations
Upgrade Lemur to version 1.9.3 or later, where the vulnerability is fixed by revalidating acme_url updates and enforcing a single allowed host for the ACME flow. No additional mitigation is required if the system is updated to this version.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-04T21:48:08.613Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a84b07ac6e8be0332a47e4c
Added to database: 08/18/2026, 19:20:26 UTC
Last enriched: 09/11/2026, 21:03:56 UTC
Last updated: 10/02/2026, 03:10:57 UTC
Views: 54
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.