Executive brief
Netflix Lemur, a tool used to manage and automate TLS certificate creation, contains a security flaw in how it connects to corporate identity directories (LDAP). When encrypted communication is enabled, the system fails to verify the identity of the directory server, allowing a nearby attacker to intercept sensitive login credentials. This could lead to unauthorized access to the certificate management system and the private keys it protects.
Technical details
A vulnerability in Lemur's LDAP authentication module (lemur/auth/ldap.py) exists due to the improper use of the global ldap.set_option() method. When LDAP_USE_TLS is enabled, the application sets OPT_X_TLS_REQUIRE_CERT to OPT_X_TLS_NEVER at the global module level, disabling certificate verification for the entire Python process. An attacker positioned on the adjacent network can perform a man-in-the-middle attack to intercept plaintext credentials or modify LDAP responses to escalate privileges. The issue is resolved in version 1.9.0 by switching to instance-level options and enforcing certificate validation.
Affected products
- Netflix Lemur < 1.9.0
Timeline
- 2026-04-28: advisory: GitHub Security Advisory published
- 2026-05-12: disclosed: CVE published to NVD
- 2026-05-12: patched: Fixed in version 1.9.0