What is CVE-2026-55165?
This vulnerability in the Lemur TLS certificate management tool allows attackers to bypass JWT verification by injecting a manipulated `alg` header from an unverified token, which is then used by the `decode_with_multiple_secrets` function. This issue affects versions prior to 1.9.2, and upgrading is required to mitigate the risk.
Azərbaycanca: CVE-2026-55165: Lemur TLS sertifikat idarəetmə vasitəsində aşkarlanan boşluqdur. 1.9.2 versiyasından əvvəl, `lemur/auth/service.py` faylındakı JWT doğrulayıcı, təsdiqlənməmiş tokendən `alg` başlığını oxuyaraq onu `decode_with_multiple_secrets` funksiyasına ötürürdü ki, bu da hücumçuya `alg=none` kimi manipulyasiya edilmiş dəyərlərlə təhlükəsizlik mexanizmini keçməyə imkan verə bilərdi. İstifadəçilər dərhal 1.9.2 versiyasına yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of Lemur are affected by CVE-2026-55165?
This vulnerability affects all versions of Lemur prior to 1.9.2.
What should be done to mitigate CVE-2026-55165?
Users must immediately upgrade Lemur to version 1.9.2.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.