1
I Use This!
Very High Activity
Analyzed 1 day ago. based on code collected 1 day ago.
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2026-9640 High Jun 26, 2026 A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project- more...
v5.21.0, 5.0.2, 5.0.1, 5.0.0
CVE-2026-9639 Medium Jun 26, 2026 Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage more...
v5.21.0, 5.0.2, 5.0.1, 5.0.0
CVE-2026-66898 Critical Aug 12, 2026 A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or more...
v5.21.0, 5.0.2, 5.0.1, 5.0.0
CVE-2026-66897 Critical Aug 24, 2026 A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafte more...
v5.21.0, 5.0.2, 5.0.1, 5.0.0
CVE-2026-63300 Critical Aug 12, 2026 An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_cre more...
v5.21.0, 5.0.2, 5.0.1, 5.0.0
CVE-2026-63299 Critical Aug 12, 2026 An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail t more...
v5.21.0, 5.0.2, 5.0.1, 5.0.0
CVE-2026-63298 Critical Aug 12, 2026 An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject more...
v5.21.0, 5.0.2, 5.0.1, 5.0.0
CVE-2026-63297 Critical Aug 12, 2026 An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target projec more...
v5.21.0, 5.0.2, 5.0.1, 5.0.0
CVE-2026-63296 Critical Aug 12, 2026 An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When mig more...
v5.21.0, 5.0.2, 5.0.1, 5.0.0
CVE-2026-63295 Medium Aug 12, 2026 An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass project-level container isolation restrictions. When a project more...
v5.21.0, 5.0.2, 5.0.1, 5.0.0