THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-v5rc-cpwc-cfpr (high) — Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist

[GHSA] GHSA-v5rc-cpwc-cfpr (high) — Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist

highgithub_advisoriesPublished 2026-08-18

GHSA-v5rc-cpwc-cfpr Severity: high CVE: CVE-2026-71303

Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist

### Summary

The fix for GHSA-v2wp-frmc-5q3v added `_validate_acme_url()` to reject `acme_url` values not in `ACME_DIRECTORY_HOST_ALLOWLIST`, but the validation is only called at **autho

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-v5rc-cpwc-cfpr