CRITICAL9.9CVE-2026-55166Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise from 0, < 1.9.2
HIGH8.8CVE-2026-48508Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermission from 0, < 1.9.1
HIGH8.8CVE-2026-48508Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermission from 0, < 1.9.1
HIGH8.1Lemur: LDAP Filter Injection enables post-authentication privilege escalation
from 0, < 1.9.0
HIGH8.1Lemur: LDAP Filter Injection enables post-authentication privilege escalation
from 0, < 1.9.0
HIGH7.5Lemur subject to insecure random generation
from 0, < 1.3.2
HIGH7.5Lemur uses static IV per key
from 0, < 0.1.5
HIGH7.5Lemur uses static IV per key
from 0, < 0.2.1
MEDIUM6.8Lemur: LDAP Authentication Globally Disables TLS Certificate Verification When LDAP_USE_TLS Is Enabled
from 0, < 1.9.0
MEDIUM6.8Lemur: LDAP Authentication Globally Disables TLS Certificate Verification When LDAP_USE_TLS Is Enabled
from 0, < 1.9.0
MEDIUM6.3Lemur Privilege Escalation: Non-admin role members can rewrite role membership via PUT /api/1/roles/<id>
from 0, < 1.9.2
MEDIUM6.3Lemur Privilege Escalation: Non-admin role members can rewrite role membership via PUT /api/1/roles/<id>
from 0, < 1.9.2
MEDIUM6.3Lemur: Crafted CRL/OCSP URLs in uploaded certificates lead to post-authentication SSRF
from 0, < 1.9.2
MEDIUM6.3Lemur: Crafted CRL/OCSP URLs in uploaded certificates lead to post-authentication SSRF
from 0, < 1.9.2
MEDIUM4.9Lemur user-update path stores plaintext passwords
from 0, < 1.9.2
MEDIUM4.9Lemur user-update path stores plaintext passwords
from 0, < 1.9.2
MEDIUM4.8Lemur: JWT verifier honors attacker-supplied alg, enabling ATO
from 0, < 1.9.2
MEDIUM4.8Lemur: JWT verifier honors attacker-supplied alg, enabling ATO
from 0, < 1.9.2