Canonical / LXD
35 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-87798 | LXD client recursive file pull allows directory escape via malicious VM agent | MEDIUM | 5.8 | Sep 28, 2026 |
| CVE-2026-87799 | Arbitrary file write on LXD host via symlink in migration stream | CRITICAL | 9.9 | Sep 28, 2026 |
| CVE-2026-97335 | Incorrect authorization in LXD storage volume API allows reading volumes from other projects | HIGH | 7.7 | Sep 28, 2026 |
| CVE-2026-85185 | Path traversal in LXD btrfs storage driver allows arbitrary file deletion and write on host as root | CRITICAL | 9.6 | Sep 28, 2026 |
| CVE-2026-85526 | Path traversal via Btrfs optimized-backup subvolumes[].path enables root file/dir manipulation in LXD | CRITICAL | 9.9 | Sep 28, 2026 |
| CVE-2026-86335 | LXD Cross-Project Private Image Theft via Unsanitized GetImageFromAnyProject Local Reuse | MEDIUM | 6.3 | Sep 28, 2026 |
| CVE-2026-86334 | CLI Path Traversal via Content-Disposition in LXD Image Export/Copy | MEDIUM | 4.2 | Sep 28, 2026 |
| CVE-2026-66897 | Instance template path traversal allows arbitrary host file write as root | CRITICAL | 9.9 | Aug 24, 2026 |
| CVE-2026-16033 | Arbitrary file read+write on host via templates/ symlink in malicious image | HIGH | 8.5 | Aug 12, 2026 |
| CVE-2026-66898 | Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE | CRITICAL | 9.9 | Aug 12, 2026 |
| CVE-2026-63293 | Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root | CRITICAL | 9.9 | Aug 12, 2026 |
| CVE-2026-63294 | Root RCE via image backup.yaml symlink | CRITICAL | 9.9 | Aug 12, 2026 |
| CVE-2026-63295 | Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated` | MEDIUM | 4.3 | Aug 12, 2026 |
| CVE-2026-63296 | Project restriction bypass via instance migration config override | CRITICAL | 9.9 | Aug 12, 2026 |
| CVE-2026-63297 | Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge | CRITICAL | 9.9 | Aug 12, 2026 |
| CVE-2026-63298 | LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration | CRITICAL | 9.9 | Aug 12, 2026 |
| CVE-2026-63299 | Storage volume cross-project move and snapshot restore bypass project disk limits | CRITICAL | 9.9 | Aug 12, 2026 |
| CVE-2026-62420 | Cross-project cluster migration bypasses project restrictions via cluster notification flag | CRITICAL | 9.9 | Aug 12, 2026 |
| CVE-2026-63300 | Cross-project instance move bypasses all project restrictions allowing host command execution | CRITICAL | 9.9 | Aug 12, 2026 |
| CVE-2026-28385 | SSRF via image import from URL allows internal network probing by authenticated users | MEDIUM | 5.0 | Jun 26, 2026 |
| CVE-2026-9640 | LXD Snapshot Import Privilege Escalation Vulnerability | HIGH | 7.2 | Jun 26, 2026 |
| CVE-2026-9639 | Authenticated Denial of Service via Malicious Backup Tarball in LXD | MEDIUM | 6.5 | Jun 26, 2026 |
| CVE-2026-12411 | Broken Access Control in Canonical LXD DevLXD API | CRITICAL | 9.6 | Jun 26, 2026 |
| CVE-2026-34179 | Update of type field in restricted TLS certificate allows privilege escalation to cluster admin | CRITICAL | 9.1 | Apr 9, 2026 |
| CVE-2026-34178 | Importing a crafted backup leads to project restriction bypass | CRITICAL | 9.1 | Apr 9, 2026 |
Showing 1 to 25 of 35 CVEs