Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

LXD — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in LXD, with AI-generated Chinese analysis, references, and POCs.

This page documents security weaknesses associated with the LXD container management platform, categorized by common weakness types and specific product tags. It aggregates a comprehensive collection of vulnerabilities affecting the LXD software stack, including container escape risks, privilege escalation flaws, and network isolation bypasses. The data covers vulnerabilities identified and published from 2017 through the present, ensuring a historical perspective on the product's security evolution. Readers can utilize this resource to track vendor advisories issued by Canonical and the broader open-source community, gaining insight into the timeline of disclosed issues and their respective severity levels. Furthermore, the page allows users to understand specific weakness classes, such as insecure default configurations or insufficient input validation, as they manifest within the LXD architecture. By examining the detailed history of vulnerabilities, developers and security professionals can analyze trends in how the product has addressed security challenges over time. This information supports risk assessment processes by providing context on the frequency and nature of past incidents, helping teams identify recurring patterns or previously unresolved edge cases. The aggregated data serves as a reference for understanding the current threat landscape surrounding LXC-based container runtimes, enabling informed decisions regarding deployment configurations and patch management strategies. This objective compilation of security data aims to enhance transparency and facilitate better security practices among administrators and developers relying on LXD for containerized workloads.

Vendor: Ubuntu

CVE IDTitleCVSSSeverityPublished
CVE-2026-28385 SSRF via image import from URL allows internal network probing by authenticated users CWE-918 5.0 Medium2026-06-26
CVE-2026-9640 LXD Snapshot Import Privilege Escalation Vulnerability CWE-863 7.2 High2026-06-26
CVE-2026-9639 Authenticated Denial of Service via Malicious Backup Tarball in LXD CWE-476 6.5 Medium2026-06-26
CVE-2026-12411 Broken Access Control in Canonical LXD DevLXD API CWE-639 8.4 High2026-06-26
CVE-2026-34179 Update of type field in restricted TLS certificate allows privilege escalation to cluster admin CWE-915 9.1 Critical2026-04-09
CVE-2026-34178 Importing a crafted backup leads to project restriction bypass CWE-20 9.1 Critical2026-04-09
CVE-2026-34177 VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf CWE-184 9.1 Critical2026-04-09
CVE-2026-28384 Authenticated RCE via unsanitized compression_algorithm CWE-78 8.8AIHighAI2026-03-12
CVE-2026-3351 Authorization Bypass in LXD GET /1.0/certificates Endpoint CWE-862 4.3AIMediumAI2026-03-03
CVE-2025-54293 Path Traversal in LXD Instance Log File Retrieval CWE-22 6.5AIMediumAI2025-10-02
CVE-2025-54292 Client-Side Path Traversal in LXD-UI CWE-22 8.1AIHighAI2025-10-02
CVE-2025-54291 Project existence disclosure in LXD images API CWE-209 5.3AIMediumAI2025-10-02
CVE-2025-54290 Project Existence Disclosure via Error Handling in LXD Image Export CWE-200 5.3AIMediumAI2025-10-02
CVE-2025-54289 Privilege Escalation via WebSocket Connection Hijacking in LXD Operations API CWE-1385 8.8AIHighAI2025-10-02
CVE-2025-54288 Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server CWE-290 5.1AIMediumAI2025-10-02
CVE-2025-54287 Arbitrary File Read via Template Injection in Snapshot Patterns CWE-1336 6.5AIMediumAI2025-10-02
CVE-2025-54286 CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI CWE-352 8.8AIHighAI2025-10-02
CVE-2024-6219 LXD 安全漏洞 3.8 Low2024-12-05
CVE-2024-6156 LXD 安全漏洞 3.8 Low2024-12-05
CVE-2023-49721 EDK2 安全漏洞 6.7 Medium2024-02-14
CVE-2015-1340 chmod race in doUidshiftIntoContainer 8.1 -2019-04-22

All 21 known CVE vulnerabilities affecting LXD with full Chinese analysis, references, and POCs where available.