Lxd
This hub aggregates every CVE we track for Lxd, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
19
CVEs tracked
4
Critical
3
High
0
In CISA KEV
Severity distribution
MEDIUM10CRITICAL4HIGH3LOW2
Monthly trend
0
0
0
0
0
2
0
0
0
0
0
0
0
0
0
8
0
0
0
0
1
3
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Lxd.
- CVE-2026-34179Update of type field in restricted TLS certificate allows privilege escalation to cluster admin9.1
- CVE-2026-34178Importing a crafted backup leads to project restriction bypass9.1
- CVE-2026-34177VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf9.1
- CVE-2026-28384Authenticated RCE via unsanitized compression_algorithm9.9
- CVE-2025-54293Path Traversal in LXD Instance Log File Retrieval6.5
- CVE-2025-54292Client-Side Path Traversal in LXD-UI4.6
- CVE-2025-54291Project existence disclosure in LXD images API5.3
- CVE-2025-54290Project Existence Disclosure via Error Handling in LXD Image Export5.3
- CVE-2025-54289Privilege Escalation via WebSocket Connection Hijacking in LXD Operations API8.1
- CVE-2025-54288Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server6.8
- CVE-2025-54287Arbitrary File Read via Template Injection in Snapshot Patterns6.5
- CVE-2025-54286CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI8.8
- CVE-2024-6219Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.3.8
- CVE-2024-6156Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.3.8
- CVE-2023-49721An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.6.7
Product normalization is registry-driven with AI assist and human review. How it works