CRITICAL9.9CVE-2026-48769Incus has an arbitrary file write on its client due to trusted image hash in github.com/lxc/incus from 0
CRITICAL9.9CVE-2026-48755Incus has an argument injection in backup compression algorithm leading to AFW and ACE in github.com/lxc/incus from 0
CRITICAL9.9CVE-2026-48752Incus has arbitrary file read+write on host via templates/ symlink in malicious image in github.com/lxc/incus from 0
CRITICAL9.9Incus has a restricted project bypass leading to arbitrary command execution in github.com/lxc/incus
from 0
CRITICAL9.9Incus has an arbitrary file write on host via `exec-output` symlink in crafted image in github.com/lxc/incus
from 0
CRITICAL9.9Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image in github.com/lxc/incus
from 0
CRITICAL9.9Incus vulnerable to arbitrary file read and write through pongo templates in github.com/lxc/incus
from 0
CRITICAL9.1LXD: VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf
from 0
CRITICAL9.1LXD: Importing a crafted backup leads to project restriction bypass
from 0
CRITICAL9.1LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin
from 0
HIGH8.8lxd - security update
from 0
HIGH8.7Incus container image templating arbitrary host file read and write in github.com/lxc/incus
from 0
HIGH8.7lxd - security update
from 0
HIGH7.8lxd - security update
from 0
HIGH7.2A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling…
from 0
MEDIUM6.8Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server in github.com/canonical/lxd
from 0
MEDIUM6.5Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_cr…
from 0
MEDIUM6.5Incus has Nil Dereferences on Restore via Malformed YAML in github.com/lxc/incus
from 0
MEDIUM6.5Incus Vulnerable to Panic via Snapshot Bounds Check in github.com/lxc/incus
from 0
MEDIUM6.5Incus has a Nil-Pointer Dereference via Custom Volume Import in github.com/lxc/incus
from 0
MEDIUM6.5Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns in github.com/lxc/lxd
from 0
MEDIUM6.5Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function in github.com/canonical/lxd
from 0
MEDIUM5.3Canonical LXD Project Existence Determination Through Error Handling in Image Export Function in github.com/canonical/lxd
from 0
MEDIUM5.3Canonical LXD Project Existence Determination Through Error Handling in Image Get Function in github.com/canonical/lxd
from 0
MEDIUM5.0In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows aut…
from 0
MEDIUM5.0Incus has Unbounded YAML Metadata Decode via Parsing in github.com/lxc/incus
from 0
MEDIUM4.8Incus does not verify combined fingerprint when downloading images from simplestreams servers in github.com/lxc/incus
from 0
MEDIUM4.3Incus is affected by unbounded binary import disk exhaustion in github.com/lxc/incus
from 0
LOW3.8CA certificate sign check bypass in github.com/canonical/lxd
from 0
—(no summary)
from 0
—(no summary)
from 0
—lxd - security update
from 0
—Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote authenticated attackers to access or m…
from 0