CVE-2026-55166 | Netflix Lemur up to 1.9.1 Acme Client AcmeHandler.setup_acme_client acme_url server-side request forgery

SecurityVulns

A vulnerability described as critical has been identified in Netflix Lemur up to 1.9.1. This impacts the function AcmeHandler.setup_acme_client of the component Acme Client. Such manipulation of the argument acme_url leads to server-side request forgery.

This vulnerability is listed as CVE-2026-55166. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More