VendorsLinux Containersincusall versions
Vulnerabilities

Linux Containers Incus

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2026-33897
Incus vulnerable to arbitrary file read and write through pongo templates
Published 2026-03-26 · Analyzed
9.9EPSS 0.005
CVE-2026-33945
Abitrary file write through systemd-creds option
Published 2026-03-26 · Analyzed
9.9EPSS 0.004
CVE-2026-33898
Local Incus UI web server vulnerable to nuthentication bypass
Published 2026-03-26 · Analyzed
8.8EPSS 0.003
CVE-2026-23954
Incus container image templating arbitrary host file read and write
Published 2026-01-22 · Analyzed
8.7EPSS 0.008
CVE-2026-23953
Incus container environment configuration newline injection
Published 2026-01-22 · Analyzed
8.7EPSS 0.005
CVE-2025-64507
Incus vulnerable to local privilege escalation through custom storage volumes
Published 2025-11-10 · Analyzed
8.6EPSS 0.002
CVE-2026-33711
Incus vulnerable to local privilege escalation through VM screenshot path
Published 2026-03-26 · Analyzed
7.8EPSS 0.004
CVE-2026-40251
Incus out-of-bounds panic in snapshot metadata handling allows denial of service
Published 2026-05-06 · Analyzed
7.1EPSS 0.004
CVE-2026-40195
Incus nil-pointer dereference in storage bucket import allows denial of service
Published 2026-05-06 · Analyzed
7.1EPSS 0.004
CVE-2026-40197
Incus nil-pointer dereference in custom volume import allows denial of service
Published 2026-05-06 · Analyzed
7.1EPSS 0.004
CVE-2026-41684
Incus: Nil Dereferences on Restore via Malformed YAML
Published 2026-05-07 · Analyzed
6.5EPSS 0.004
CVE-2026-41647
Incus: Nil-Pointer Dereference via S3 Bucket Import
Published 2026-05-07 · Analyzed
6.5EPSS 0.004
CVE-2026-33743
Incus vulnerable to denial of source through crafted bucket backup file
Published 2026-03-26 · Analyzed
6.5EPSS 0.004
CVE-2026-33542
Incus does not verify combined fingerprint when downloading images from simplestreams servers
Published 2026-03-26 · Analyzed
5.7EPSS 0.002
CVE-2026-35527
Incus blind SSRF via image import preflight HEAD request
Published 2026-05-05 · Analyzed
5.3EPSS 0.003
CVE-2026-41648
Incus: Unbounded YAML Metadata Decode via Parsing
Published 2026-05-07 · Analyzed
5.3EPSS 0.003
CVE-2026-40243
Incus OVN TLS verification accepts peer-supplied roots and permits endpoint impersonation
Published 2026-05-06 · Analyzed
4.8EPSS 0.002
CVE-2026-41685
Incus: Unbounded binary import disk exhaustion
Published 2026-05-07 · Analyzed
4.3EPSS 0.003