Linuxcontainers / Incus
18 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-41685 | Incus: Unbounded binary import disk exhaustion | MEDIUM | 4.3 | May 7, 2026 |
| CVE-2026-41684 | Incus: Nil Dereferences on Restore via Malformed YAML | MEDIUM | 6.5 | May 7, 2026 |
| CVE-2026-41648 | Incus: Unbounded YAML Metadata Decode via Parsing | MEDIUM | 5.3 | May 7, 2026 |
| CVE-2026-41647 | Incus: Nil-Pointer Dereference via S3 Bucket Import | MEDIUM | 6.5 | May 7, 2026 |
| CVE-2026-40251 | Incus out-of-bounds panic in snapshot metadata handling allows denial of service | HIGH | 7.1 | May 6, 2026 |
| CVE-2026-40243 | Incus OVN TLS verification accepts peer-supplied roots and permits endpoint impersonation | LOW | 2.3 | May 6, 2026 |
| CVE-2026-40197 | Incus nil-pointer dereference in custom volume import allows denial of service | HIGH | 7.1 | May 6, 2026 |
| CVE-2026-40195 | Incus nil-pointer dereference in storage bucket import allows denial of service | HIGH | 7.1 | May 6, 2026 |
| CVE-2026-35527 | Incus blind SSRF via image import preflight HEAD request | MEDIUM | 5.3 | May 5, 2026 |
| CVE-2026-33945 | Abitrary file write through systemd-creds option | CRITICAL | 10.0 | Mar 26, 2026 |
| CVE-2026-33898 | Local Incus UI web server vulnerable to nuthentication bypass | HIGH | 8.8 | Mar 26, 2026 |
| CVE-2026-33897 | Incus vulnerable to arbitrary file read and write through pongo templates | CRITICAL | 10.0 | Mar 26, 2026 |
| CVE-2026-33743 | Incus vulnerable to denial of source through crafted bucket backup file | MEDIUM | 6.5 | Mar 26, 2026 |
| CVE-2026-33711 | Incus vulnerable to local privilege escalation through VM screenshot path | MEDIUM | 4.7 | Mar 26, 2026 |
| CVE-2026-33542 | Incus does not verify combined fingerprint when downloading images from simplestreams servers | HIGH | 7.0 | Mar 26, 2026 |
| CVE-2026-23954 | Incus container image templating arbitrary host file read and write | HIGH | 8.7 | Jan 22, 2026 |
| CVE-2026-23953 | Incus container environment configuration newline injection | HIGH | 8.7 | Jan 22, 2026 |
| CVE-2025-64507 | Incus vulnerable to local privilege escalation through custom storage volumes | HIGH | 8.6 | Nov 10, 2025 |
Showing 1 to 18 of 18 CVEs