Lxd
This hub aggregates every CVE we track for Lxd, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
23
CVEs tracked
4
Critical
5
High
0
In CISA KEV
Severity distribution
MEDIUM12HIGH5CRITICAL4LOW2
Monthly trend
0
0
0
2
0
0
0
0
0
0
0
0
0
8
0
0
0
0
1
3
0
4
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Lxd.
- CVE-2026-28385SSRF via image import from URL allows internal network probing by authenticated users5.0
- CVE-2026-9640LXD Snapshot Import Privilege Escalation Vulnerability7.2
- CVE-2026-9639Authenticated Denial of Service via Malicious Backup Tarball in LXD6.5
- CVE-2026-12411Broken Access Control in Canonical LXD DevLXD API8.4
- CVE-2026-34179Update of type field in restricted TLS certificate allows privilege escalation to cluster admin9.1
- CVE-2026-34178Importing a crafted backup leads to project restriction bypass9.1
- CVE-2026-34177VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf9.1
- CVE-2026-28384Authenticated RCE via unsanitized compression_algorithm9.9
- CVE-2025-54293Path Traversal in LXD Instance Log File Retrieval6.5
- CVE-2025-54292Client-Side Path Traversal in LXD-UI4.6
- CVE-2025-54291Project existence disclosure in LXD images API5.3
- CVE-2025-54290Project Existence Disclosure via Error Handling in LXD Image Export5.3
- CVE-2025-54289Privilege Escalation via WebSocket Connection Hijacking in LXD Operations API8.1
- CVE-2025-54288Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server6.8
- CVE-2025-54287Arbitrary File Read via Template Injection in Snapshot Patterns6.5
Product normalization is registry-driven with AI assist and human review. How it works