CVE-2026-55165 | Netflix Lemur up to 1.9.1 JWT Verifier lemur/auth/service.py fetch_token_header alg certificate validation

SecurityVulns

A vulnerability categorized as problematic has been discovered in Netflix Lemur up to 1.9.1. Impacted is the function fetch_token_header of the file lemur/auth/service.py of the component JWT Verifier. Executing a manipulation of the argument alg can lead to improper certificate validation.

The identification of this vulnerability is CVE-2026-55165. The attack may be launched remotely. There is no exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More