THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-xpmj-wjcp-6pww (high) — Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs

[GHSA] GHSA-xpmj-wjcp-6pww (high) — Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs

highgithub_advisoriesPublished 2026-08-18

GHSA-xpmj-wjcp-6pww Severity: high CVE: CVE-2026-70666

Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs

### Summary The ACME client (used to issue certificates from Let's Encrypt / Google Public CA / private ACME CAs) connects to an `acme_url`, then issues requests to URLs that the **ACME server returns** in its directory/order/authorization/finalize respon

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-xpmj-wjcp-6pww