Junglewise Threat Intelligence

CVE-2026-44305: Netflix Lemur TLS certificate verification bypass in LDAP authentication

CVE-2026-44305 · Severity: medium · CVSS 6.8 · Published 2026-05-12

Technologies: lemur (PyPI). Vendors: PyPI.

Executive brief

Netflix Lemur, a tool used to manage and automate TLS certificate creation, contains a security flaw in how it connects to corporate identity directories (LDAP). When encrypted communication is enabled, the system fails to verify the identity of the directory server, allowing a nearby attacker to intercept sensitive login credentials. This could lead to unauthorized access to the certificate management system and the private keys it protects.

Technical details

A vulnerability in Lemur's LDAP authentication module (lemur/auth/ldap.py) exists due to the improper use of the global ldap.set_option() method. When LDAP_USE_TLS is enabled, the application sets OPT_X_TLS_REQUIRE_CERT to OPT_X_TLS_NEVER at the global module level, disabling certificate verification for the entire Python process. An attacker positioned on the adjacent network can perform a man-in-the-middle attack to intercept plaintext credentials or modify LDAP responses to escalate privileges. The issue is resolved in version 1.9.0 by switching to instance-level options and enforcing certificate validation.

Affected products

  • Netflix Lemur < 1.9.0

Timeline

  • 2026-04-28: advisory: GitHub Security Advisory published
  • 2026-05-12: disclosed: CVE published to NVD
  • 2026-05-12: patched: Fixed in version 1.9.0

References

Related threats