Search CVE reports


Toggle filters

31 – 40 of 110 results


CVE-2026-63295

Medium priority
Needs evaluation

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project is configured with restrictions on container privileges (such as enforcing...

1 affected package

lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lxd Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-63294

Medium priority
Needs evaluation

A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the...

1 affected package

lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lxd Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-63293

Medium priority
Needs evaluation

A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is...

1 affected package

lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lxd Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-62420

Medium priority
Needs evaluation

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster...

1 affected package

lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lxd Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-28385

Medium priority
Not affected

In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows authenticated users with the can_create_images entitlement to interact with internal network...

1 affected package

lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lxd Not in release Not in release Not in release Not affected Not affected
Show less packages

CVE-2026-9640

Medium priority
Not affected

A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration.. An authenticated project...

1 affected package

lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lxd Not in release Not in release Not in release Not affected Not affected
Show less packages

CVE-2026-9639

Medium priority
Not affected

Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted...

1 affected package

lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lxd Not in release Not in release Not in release Not affected Not affected
Show less packages

CVE-2026-12411

Medium priority
Not affected

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device PATCH request over /dev/lxd when...

1 affected package

lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lxd Not in release Not in release Not in release Not affected Not affected
Show less packages

CVE-2026-39821

High priority

Some fixes available 6 of 65

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This...

27 affected packages

golang-golang-x-net, google-guest-agent, google-osconfig-agent, containerd, adsys...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Vulnerable Vulnerable Fixed Not in release Not in release
google-guest-agent Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
google-osconfig-agent Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
containerd Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
adsys Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
juju-core — — — — —
lxd — — — Needs evaluation Needs evaluation
golang Not in release Not in release Not in release Not in release Not in release
golang-1.6 Not in release Not in release Not in release Not in release Not in release
golang-1.8 Not in release Not in release Not in release Not in release Needs evaluation
golang-1.9 Not in release Not in release Not in release Not in release Needs evaluation
golang-1.10 Not in release Not in release Not in release Not in release Needs evaluation
golang-1.13 Not in release Not in release Needs evaluation Needs evaluation Needs evaluation
golang-1.14 Not in release Not in release Not in release Needs evaluation Not in release
golang-1.16 Not in release Not in release Not in release Needs evaluation Needs evaluation
golang-1.17 Not in release Not in release Needs evaluation Not in release Not in release
golang-1.18 Not in release Not in release Fixed Needs evaluation Needs evaluation
golang-1.19 Not in release Not in release Not in release Not in release Not in release
golang-1.20 Not in release Not in release Needs evaluation Needs evaluation Not in release
golang-1.21 Not in release Needs evaluation Fixed Needs evaluation Not in release
golang-1.22 Not in release Needs evaluation Needs evaluation Needs evaluation Not in release
golang-1.23 Needs evaluation Needs evaluation Needs evaluation Not in release Not in release
golang-1.24 Needs evaluation Needs evaluation Fixed Not in release Not in release
golang-1.25 Needs evaluation Not in release Not in release Not in release Not in release
golang-1.26 Needs evaluation Not in release Not in release Not in release Not in release
golang-1.27 Not in release Not in release Not in release Not in release Not in release
golang-golang-x-net-dev Not in release Not in release Not in release Fixed Fixed
Show all 27 packages Show less packages

CVE-2026-46598

Medium priority
Needs evaluation

For certain crafted inputs, a 'ed25519.PrivateKey' was created by casting malformed wire bytes, leading to a panic when used.

4 affected packages

golang-go.crypto, snapd, google-guest-agent, lxd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-go.crypto Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
snapd Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
google-guest-agent Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
lxd Not in release Not in release Not in release Not affected Needs evaluation
Show less packages