What is CVE-2026-55162?
In Lemur TLS certificate management tool versions prior to 1.9.2, an authenticated operator could upload certificates with crafted CRL Distribution Point or OCSP responder URLs, which were then used in `crl_verify` and `ocsp_verify` without destination validation. This could enable SSRF-like attacks against internal network resources. Affected deployments should upgrade to version 1.9.2 immediately.
Azərbaycanca: Lemur TLS sertifikat idarəetmə alətinin 1.9.2-dən əvvəlki versiyalarında, autentifikasiya olunmuş operator xüsusi hazırlanmış sertifikat yükləyərək CRL Distribution Point və OCSP responder URL-lərini manipulyasiya edə bilər. Bu, `crl_verify` və `ocsp_verify` əməliyyatlarını təhlükəli istiqamətlərə yönləndirərək şəbəkə resurslarına qarşı SSRF və ya digər hücumlara səbəb ola bilər. Təsirlənən sistem dərhal 1.9.2 versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of the Lemur TLS certificate management tool are affected by CVE-2026-55162?
All versions of Lemur prior to 1.9.2 are affected by this vulnerability.
How can I protect against this vulnerability?
Affected deployments should upgrade to version 1.9.2 immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.