lemur vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-55166Criticallemur: Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromiseCVE-2026-55165Mediumlemur: Lemur: JWT verifier honors attacker-supplied alg, enabling ATOCVE-2026-55164Mediumlemur: Lemur user-update path stores plaintext passwordsCVE-2026-55163Mediumlemur: Lemur Privilege Escalation: Non-admin role members can rewrite role membership via PUT /api/1/roles/<id>CVE-2026-55162Mediumlemur: Lemur: Crafted CRL/OCSP URLs in uploaded certificates lead to post-authentication SSRFCVE-2026-48508Highlemur: Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermissionCVE-2026-44304Highlemur: Lemur: LDAP Filter Injection enables post-authentication privilege escalationCVE-2026-44305Mediumlemur: Lemur: LDAP Authentication Globally Disables TLS Certificate Verification When LDAP_USE_TLS Is EnabledCVE-2023-30797Highlemur: Lemur subject to insecure random generationCVE-2015-7764Highlemur: Lemur uses static IV per key

Stop the waste.
Protect your environment with Kodem.