VendorsCanonicallxdall versions
Vulnerabilities

Canonical LXD

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

35CVEs
CVE-2026-63294
Root RCE via image backup.yaml symlink
Published 2026-08-12 · Analyzed
9.9EPSS 0.009
CVE-2026-28384
Authenticated RCE via unsanitized compression_algorithm
Published 2026-03-12 · Analyzed
9.9EPSS 0.009
CVE-2026-66897
Instance template path traversal allows arbitrary host file write as root
Published 2026-08-24 · Analyzed
9.9EPSS 0.007
CVE-2026-63298
LXD arbitrary lxc.conf directive injection via NVIDIA instance configuration
Published 2026-08-12 · Analyzed
9.9EPSS 0.007
CVE-2026-63293
Arbitrary File Read/Write: metadata.yaml symlink in image allows host filesystem access as root
Published 2026-08-12 · Analyzed
9.9EPSS 0.006
CVE-2026-66898
Path traversal via unvalidated instance name in backup tarball restore enables root file write / RCE
Published 2026-08-12 · Analyzed
9.9EPSS 0.006
CVE-2026-63299
Storage volume cross-project move and snapshot restore bypass project disk limits
Published 2026-08-12 · Analyzed
9.9EPSS 0.006
CVE-2026-62420
Cross-project cluster migration bypasses project restrictions via cluster notification flag
Published 2026-08-12 · Analyzed
9.9EPSS 0.005
CVE-2026-63300
Cross-project instance move bypasses all project restrictions allowing host command execution
Published 2026-08-12 · Analyzed
9.9EPSS 0.005
CVE-2026-63296
Project restriction bypass via instance migration config override
Published 2026-08-12 · Analyzed
9.9EPSS 0.004
CVE-2026-63297
Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge
Published 2026-08-12 · Analyzed
9.9EPSS 0.003
CVE-2026-12411
Broken Access Control in Canonical LXD DevLXD API
Published 2026-06-26 · Analyzed
9.6EPSS 0.003
CVE-2026-34178
Importing a crafted backup leads to project restriction bypass
Published 2026-04-09 · Analyzed
9.1EPSS 0.007
CVE-2026-34177
VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf
Published 2026-04-09 · Analyzed
9.1EPSS 0.006
CVE-2026-34179
Update of type field in restricted TLS certificate allows privilege escalation to cluster admin
Published 2026-04-09 · Analyzed
9.1EPSS 0.004
CVE-2025-54286
CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI
Published 2025-10-02 · Analyzed
8.8EPSS 0.001
CVE-2026-16033
Arbitrary file read+write on host via templates/ symlink in malicious image
Published 2026-08-12 · Analyzed
8.5EPSS 0.004
CVE-2025-54289
Privilege Escalation via WebSocket Connection Hijacking in LXD Operations API
Published 2025-10-02 · Analyzed
8.1EPSS 0.002
CVE-2026-9640
LXD Snapshot Import Privilege Escalation Vulnerability
Published 2026-06-26 · Analyzed
7.2EPSS 0.006
CVE-2025-54293
Path Traversal in LXD Instance Log File Retrieval
Published 2025-10-02 · Analyzed
7.1EPSS 0.006
CVE-2025-54287
Arbitrary File Read via Template Injection in Snapshot Patterns
Published 2025-10-02 · Analyzed
7.1EPSS 0.004
CVE-2025-54291
Project existence disclosure in LXD images API
Published 2025-10-02 · Analyzed
6.9EPSS 0.004
CVE-2025-54290
Project Existence Disclosure via Error Handling in LXD Image Export
Published 2025-10-02 · Analyzed
6.9EPSS 0.003
CVE-2025-54288
Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server
Published 2025-10-02 · Analyzed
6.8EPSS 0.004
CVE-2023-48733
An insecure default to allow UEFI Shell in EDK2 was left enabled in Ubuntu's EDK2. This allows an OS-resident attacker to bypass Secure Boot.
Published 2024-02-14 · Analyzed
6.7EPSS 0.003
CVE-2023-49721
An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass Secure Boot.
Published 2024-02-14 · Analyzed
6.7EPSS 0.002
CVE-2026-9639
Authenticated Denial of Service via Malicious Backup Tarball in LXD
Published 2026-06-26 · Analyzed
6.5EPSS 0.005
CVE-2016-1582
LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access arbitrary world readable paths in the container directory via unspecified vectors.
Published 2016-06-09 · Modified
5.5EPSS 0.003
CVE-2016-1581
LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and read data from arbitrary containers via unspecified vectors.
Published 2016-06-09 · Modified
5.5EPSS 0.003
CVE-2026-28385
SSRF via image import from URL allows internal network probing by authenticated users
Published 2026-06-26 · Analyzed
5.0EPSS 0.003
CVE-2025-54292
Client-Side Path Traversal in LXD-UI
Published 2025-10-02 · Analyzed
4.8EPSS 0.003
CVE-2026-63295
Project restriction `restricted.containers.privilege=isolated` bypassable by omitting `security.idmap.isolated`
Published 2026-08-12 · Analyzed
4.3EPSS 0.003
CVE-2026-3351
Authorization Bypass in LXD GET /1.0/certificates Endpoint
Published 2026-03-03 · Analyzed
4.3EPSS 0.002
CVE-2024-6156
Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
Published 2024-12-05 · Analyzed
3.8EPSS 0.002
CVE-2024-6219
Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.
Published 2024-12-05 · Analyzed
3.8EPSS 0.002