THREAT OPS › Threat News › [GHSA] GHSA-v5rc-cpwc-cfpr (high) — Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist
[GHSA] GHSA-v5rc-cpwc-cfpr (high) — Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist
GHSA-v5rc-cpwc-cfpr Severity: high CVE: CVE-2026-71303
Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist
### Summary
The fix for GHSA-v2wp-frmc-5q3v added `_validate_acme_url()` to reject `acme_url` values not in `ACME_DIRECTORY_HOST_ALLOWLIST`, but the validation is only called at **autho
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-71303cve
- http://169.254.169.254/latest/meta-data/\url
- http://169.254.169.254/latest/meta-data/url
- http://169.254.169.254/latest/meta-data/`url
- acme-v02.api.letsencrypt.orgdomain
Original source: https://github.com/advisories/GHSA-v5rc-cpwc-cfpr