github.com/lxc/incus/v7
Go15 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/lxc/incus/v7page 1 of 1
- CVE-2026-35527MEDIUMCVSS 5.0EG 5.0✓ Fixed in 7.0.02026-05-05
Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an outbound HEAD request to a user-supplied URL before validating the request against project restrictions such as rest…
- CVE-2026-40195MEDIUMCVSS 6.5EG 6.5✓ Fixed in 7.0.02026-05-06
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage bucket import logic allows an authenticated user with access to the storage bucket feature to cause the Incus daemon…
- CVE-2026-40197MEDIUMCVSS 6.5EG 6.5✓ Fixed in 7.0.02026-05-06
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon…
- CVE-2026-40243MEDIUMCVSS 4.8EG 4.8✓ Fixed in 7.0.02026-05-06
Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN database connection logic can allow connections to an attacker's OVN database. The OVN client implementations disable…
- CVE-2026-40251MEDIUMCVSS 6.5EG 6.5✓ Fixed in 7.0.02026-05-06
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon…
- CVE-2026-47753MEDIUMEG 0.0✓ Fixed in 7.1.02026-06-10
Incus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted) ## Summary `(*backend).CreateInstanceFromBackup` in [`internal/server/storage/backend.go`](https://github.com/lxc/incus/blob/1513600/internal/server/st…
- CVE-2026-48749CRITICALCVSS 9.9EG 9.9✓ Fixed in 7.2.02026-06-26
Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image ### Summary A specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution.…
- CVE-2026-48750CRITICALCVSS 9.9EG 9.9✓ Fixed in 7.2.02026-06-26
Incus has an arbitrary file write on host via `exec-output` symlink in crafted image ### Summary The `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the…
- CVE-2026-48751CRITICALCVSS 9.9EG 9.9✓ Fixed in 7.2.02026-06-26
Incus has a restricted project bypass leading to arbitrary command execution ### Summary Instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusin…
- CVE-2026-48752CRITICALCVSS 9.9EG 9.9✓ Fixed in 7.2.02026-06-26
Incus has arbitrary file read+write on host via templates/ symlink in malicious image ### Summary A specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary…
- CVE-2026-48753CRITICALCVSS 9.9EG 9.9✓ Fixed in 7.1.02026-06-26
Incus has an arbitrary file write via path traversal in S3 multipart upload ## Summary The S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitr…
- CVE-2026-48754LOWEG 0.0✓ Fixed in 7.1.02026-06-26
Incus: Nil-pointer dereference in createDependentVolumesFromBackup on disk.{Volume,VolumeSnapshots,Pool} ## Summary `(*backend).createDependentVolumesFromBackup` in [`internal/server/storage/backend.go`](https://github.com/lxc/incus/blo…
- CVE-2026-48755CRITICALCVSS 9.9EG 9.9✓ Fixed in 7.2.02026-06-26
Incus has an argument injection in backup compression algorithm leading to AFW and ACE ### Summary Improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads …
- CVE-2026-48756LOWEG 0.0✓ Fixed in 7.1.02026-06-26
Incus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapshots[*].expires_at (sibling-field variant of GHSA-r7w7) ## Summary `(*backend).CreateCustomVolumeFromBackup` in [`internal/server/storage/backend.go`](https://git…
- CVE-2026-48769CRITICALCVSS 9.9EG 9.9✓ Fixed in 7.2.02026-06-26
Incus has an arbitrary file write on its client due to trusted image hash ### Summary An arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrar…
Check whether github.com/lxc/incus/v7 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/lxc/incus/v7 CVEs against the assets you own.
Start Free Scan →