Incus blind SSRF via image import preflight HEAD request
Published May 5, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.29%
Description
Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an outbound HEAD request to a user-supplied URL before validating the request against project restrictions such as restricted.images.servers. The imgPostURLInfo function constructs and sends a HEAD request directly from the attacker-supplied source URL to resolve image metadata, and this network interaction occurs before the flow reaches the point where the import would be rejected by policy. Although the actual image download is blocked by the project restriction, an authenticated user can coerce the daemon into making blind HEAD requests to arbitrary destinations.
These requests include server metadata in custom headers (Incus-Server-Architectures, Incus-Server-Version), which discloses information about the host environment to the attacker-controlled endpoint. This blind SSRF primitive can be used to probe internal services, unroutable address space, or cloud metadata endpoints reachable from the host.
This vulnerability pattern is similar to CVE-2026-24767. This issue has been fixed in version 7.0.0.
Affected products
-
- Version < 7.0.0StatusaffectedConstraints-
- Version
- < 7.0.0
No data.
No Red Hat product state for this CVE.
github.com/lxc/incus/v6/cmd/incusd
Go
Introduced 0 Fixed 7.0.0github.com/lxc/incus
Go
Introduced 0 Fixed not fixedgithub.com/lxc/incus/v6
Go
Introduced 0 Fixed not fixedgithub.com/lxc/incus/v7
Go
Introduced 0 Fixed 7.0.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/lxc/incus/v6/cmd/incusd | 0 | 7.0.0 |
| Go | github.com/lxc/incus | 0 | not fixed |
| Go | github.com/lxc/incus/v6 | 0 | not fixed |
| Go | github.com/lxc/incus/v7 | 0 | 7.0.0 |
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
1 other source (GHSA) ▾
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed May 6, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
May–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.29% (0.00290) | 19.50th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.27% (0.00271) | 18.66th | v5 (v2026.06.15) |
| May 6, 2026 | 0.04% (0.00038) | 11.33th | v4 (v2025.03.14) |
References (4)
- https://github.com/advisories/GHSA-8gw4-p4wq-4hcv Advisory
- https://github.com/lxc/incus/blob/v6.22.0/cmd/incusd/images.go x_refsource_MISCProduct
- https://github.com/lxc/incus/security/advisories/GHSA-8gw4-p4wq-4hcv exploitx_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-35527
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-8gw4-p4wq-4hcv | Advisory | |
| https://github.com/lxc/incus/blob/v6.22.0/cmd/incusd/images.go | x_refsource_MISCProduct | |
| https://github.com/lxc/incus/security/advisories/GHSA-8gw4-p4wq-4hcv | exploitx_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-35527 |
Change history (0)
No recorded changes yet.