CVE-2026-55166 | Netflix Lemur up to 1.9.1 Acme Client AcmeHandler.setup_acme_client acme_url server-side request forgery
A vulnerability described as critical has been identified in Netflix Lemur up to 1.9.1. This impacts the function AcmeHandler.setup_acme_client of the component Acme Client. Such manipulation of the argument acme_url leads to server-side request forgery.
This vulnerability is listed as CVE-2026-55166. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More