
CVE-2026-40611 Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 challenge provider in lego is vulnerable to arbitrary file write and … https://www.cve.org/CVERecord?id=CVE-2026-40611
Post summary
The text reports a CVE describing an arbitrary file write vulnerability in Let's Encrypt's Lego client prior to version 4.34.0, without mentioning PoC, exploit code, patch, or active exploitation.

