<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:07:39.839959+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-318005</id>
    <title>EUVD-2026-318005</title>
    <updated>2026-10-02T11:07:39.903505+00:00</updated>
    <content>EUVD-2026-318005</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-318005"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44305</id>
    <title>fkie_cve-2026-44305</title>
    <updated>2026-10-02T11:07:39.903542+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled (LDAP_USE_TLS = True), Lemur's LDAP authentication module unconditionally disables TLS certificate verification at the global ldap module level. This allows a man-in-the-middle attacker positioned between Lemur and the LDAP server to intercept all authentication credentials. This vulnerability is fixed in 1.9.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44305"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vr7c-r5gj-j3w5</id>
    <title>GHSA-vr7c-r5gj-j3w5 — Lemur: LDAP Authentication Globally Disables TLS Certificate Verification When LDAP_USE_TLS Is Enabled</title>
    <updated>2026-10-02T11:07:39.903576+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: lemur</p>
<p>## Description</p>
<p>### Overview</p>
<p>When LDAP TLS is enabled (`LDAP_USE_TLS = True`), Lemur's LDAP authentication module unconditionally disables TLS certificate verification at the **global** `ldap` module level. This allows a man-in-the-middle attacker positioned between Lemur and the LDAP server to intercept all authentication credentials.</p>
<p>### Vulnerable Code</p>
<p>**Location:** `lemur/auth/ldap.py`, `_bind()` method, line ~172</p>
<p>```python
if self.ldap_use_tls:
    ldap.set_option(ldap.OPT_X_TLS_REQUIRE_CERT, ldap.OPT_X_TLS_NEVER)
```</p>
<p>Key issues:</p>
<p>1. `ldap.set_option()` is a **global** call (as opposed to `self.ldap_client.set_option()`), meaning it disables TLS verification for the entire Python process, not just this connection
2. `OPT_X_TLS_NEVER` means no certificate validation is performed whatsoever — self-signed, expired, wrong hostname, and revoked certificates are all silently accepted
3. There is no configuration option to override this behavior — TLS verification is always disabled when TLS is enabled</p>
<p>### Impact</p>
<p>A network-positioned attacker (man-in-the-middle) between Lemur and the LDAP server can:</p>
<p>- **Intercept all LDAP credentials** (usernames and plaintext passwords) for every user who authenticates
- **Modify LDAP responses** to inject arbitrary group memberships, granting admin access
- **Compromise the entire PKI infrastructure** managed by Lemur, since authentication controls access to certificates and private keys</p>
<p>This is particularly severe because Lemur is…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vr7c-r5gj-j3w5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2590</id>
    <title>PYSEC-2026-2590 — Lemur: LDAP Authentication Globally Disables TLS Certificate Verification When LDAP_USE_TLS Is Enabled</title>
    <updated>2026-10-02T11:07:39.903635+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: lemur</p>
<p>## Description</p>
<p>### Overview</p>
<p>When LDAP TLS is enabled (`LDAP_USE_TLS = True`), Lemur's LDAP authentication module unconditionally disables TLS certificate verification at the **global** `ldap` module level. This allows a man-in-the-middle attacker positioned between Lemur and the LDAP server to intercept all authentication credentials.</p>
<p>### Vulnerable Code</p>
<p>**Location:** `lemur/auth/ldap.py`, `_bind()` method, line ~172</p>
<p>```python
if self.ldap_use_tls:
    ldap.set_option(ldap.OPT_X_TLS_REQUIRE_CERT, ldap.OPT_X_TLS_NEVER)
```</p>
<p>Key issues:</p>
<p>1. `ldap.set_option()` is a **global** call (as opposed to `self.ldap_client.set_option()`), meaning it disables TLS verification for the entire Python process, not just this connection
2. `OPT_X_TLS_NEVER` means no certificate validation is performed whatsoever — self-signed, expired, wrong hostname, and revoked certificates are all silently accepted
3. There is no configuration option to override this behavior — TLS verification is always disabled when TLS is enabled</p>
<p>### Impact</p>
<p>A network-positioned attacker (man-in-the-middle) between Lemur and the LDAP server can:</p>
<p>- **Intercept all LDAP credentials** (usernames and plaintext passwords) for every user who authenticates
- **Modify LDAP responses** to inject arbitrary group memberships, granting admin access
- **Compromise the entire PKI infrastructure** managed by Lemur, since authentication controls access to certificates and private keys</p>
<p>This is particularly severe because Lemur is…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2590"/>
  </entry>
</feed>
