THREAT OPS › Threat News › [GHSA] GHSA-xpmj-wjcp-6pww (high) — Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs
[GHSA] GHSA-xpmj-wjcp-6pww (high) — Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs
GHSA-xpmj-wjcp-6pww Severity: high CVE: CVE-2026-70666
Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs
### Summary The ACME client (used to issue certificates from Let's Encrypt / Google Public CA / private ACME CAs) connects to an `acme_url`, then issues requests to URLs that the **ACME server returns** in its directory/order/authorization/finalize respon
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-70666cve
- https://evil.attacker.tld/dirurl
- http://169.254.169.254/url
- https://evil.attacker.tld/nonceurl
- http://169.254.169.254/latest/meta-data/url
- https://evil.attacker.tld/revokeurl
- https://evil.attacker.tld/keyurl
- https://evil.attacker.tld/dir\url
- http://169.254.169.254/...`url
- attacker@corp.comemail
- acme-v02.api.letsencrypt.orgdomain
- acme-staging-v02.api.letsencrypt.orgdomain
Original source: https://github.com/advisories/GHSA-xpmj-wjcp-6pww