Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

lxd — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in lxd, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of Common Weakness Enumeration (CWE) vulnerabilities associated with the LXD container management system. It focuses on identifying security flaws within the open-source container hypervisor, allowing administrators and security researchers to assess the risk profile of their deployment environments effectively. The data collected here encompasses a wide variety of vulnerability types, including privilege escalation flaws, information disclosure leaks, denial of service conditions, and improper access control issues. The coverage spans historical records dating back to the early adoption of LXD by Canonical, ensuring that both legacy and recent security patches are accounted for. By aggregating data from vendor advisories, public vulnerability databases, and community reports, this resource offers a holistic view of the threat landscape specific to LXD implementations over time. Users of this resource can track a vendor's advisories to stay informed about critical updates and recommended mitigations. You can also understand a weakness class by examining how specific CWE identifiers manifest within the LXD codebase or related components. Furthermore, the page allows you to look up a product's vulnerability history, providing context on the frequency and severity of reported issues. This historical perspective helps teams prioritize patching efforts and improve their overall security posture. The information is structured to facilitate quick cross-referencing between vulnerability identifiers and their corresponding descriptions, ensuring that technical teams can efficiently evaluate the impact of known issues on their infrastructure without needing to consult multiple disparate sources.

Vendor: Ubuntu

CVE IDTitleCVSSSeverityPublished
CVE-2026-28385 SSRF via image import from URL allows internal network probing by authenticated users CWE-918 5.0 Medium2026-06-26
CVE-2026-9640 LXD Snapshot Import Privilege Escalation Vulnerability CWE-863 7.2 High2026-06-26
CVE-2026-9639 Authenticated Denial of Service via Malicious Backup Tarball in LXD CWE-476 6.5 Medium2026-06-26
CVE-2026-12411 Broken Access Control in Canonical LXD DevLXD API CWE-639 8.4 High2026-06-26
CVE-2026-34179 Update of type field in restricted TLS certificate allows privilege escalation to cluster admin CWE-915 9.1 Critical2026-04-09
CVE-2026-34178 Importing a crafted backup leads to project restriction bypass CWE-20 9.1 Critical2026-04-09
CVE-2026-34177 VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf CWE-184 9.1 Critical2026-04-09
CVE-2026-28384 Authenticated RCE via unsanitized compression_algorithm CWE-78 8.8AIHighAI2026-03-12
CVE-2026-3351 Authorization Bypass in LXD GET /1.0/certificates Endpoint CWE-862 4.3AIMediumAI2026-03-03
CVE-2025-54293 Path Traversal in LXD Instance Log File Retrieval CWE-22 6.5AIMediumAI2025-10-02
CVE-2025-54292 Client-Side Path Traversal in LXD-UI CWE-22 8.1AIHighAI2025-10-02
CVE-2025-54291 Project existence disclosure in LXD images API CWE-209 5.3AIMediumAI2025-10-02
CVE-2025-54290 Project Existence Disclosure via Error Handling in LXD Image Export CWE-200 5.3AIMediumAI2025-10-02
CVE-2025-54289 Privilege Escalation via WebSocket Connection Hijacking in LXD Operations API CWE-1385 8.8AIHighAI2025-10-02
CVE-2025-54288 Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server CWE-290 5.1AIMediumAI2025-10-02
CVE-2025-54287 Arbitrary File Read via Template Injection in Snapshot Patterns CWE-1336 6.5AIMediumAI2025-10-02
CVE-2025-54286 CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI CWE-352 8.8AIHighAI2025-10-02
CVE-2024-6219 LXD 安全漏洞 3.8 Low2024-12-05
CVE-2024-6156 LXD 安全漏洞 3.8 Low2024-12-05
CVE-2023-49721 EDK2 安全漏洞 6.7 Medium2024-02-14
CVE-2015-1340 chmod race in doUidshiftIntoContainer 8.1 -2019-04-22

All 21 known CVE vulnerabilities affecting lxd with full Chinese analysis, references, and POCs where available.