github.com/lxc/incus/v7
Go17 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/lxc/incus/v7page 1 of 1
- CVE-2026-35527MEDIUMCVSS 5.0EG 5.0fixed in 7.0.02026-05-05
Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an outbound HEAD request to a user-supplied URL before validating the request against project restrictions such as rest…
- CVE-2026-40195MEDIUMCVSS 6.5EG 6.5fixed in 7.0.02026-05-06
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage bucket import logic allows an authenticated user with access to the storage bucket feature to cause the Incus daemon…
- CVE-2026-40197MEDIUMCVSS 6.5EG 6.5fixed in 7.0.02026-05-06
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon…
- CVE-2026-40243MEDIUMCVSS 4.8EG 4.8fixed in 7.0.02026-05-06
Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN database connection logic can allow connections to an attacker's OVN database. The OVN client implementations disable…
- CVE-2026-40251MEDIUMCVSS 6.5EG 6.5fixed in 7.0.02026-05-06
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon…
- CVE-2026-47753MEDIUMCVSS 4.4EG 4.4fixed in 7.1.02026-06-10
Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateInstanceFromBackup` in `internal/server/storage/backend.go` contains a nil-pointer dereference that an authenticated user with permission to…
- CVE-2026-48749CRITICALCVSS 9.9EG 9.9fixed in 7.2.02026-06-26
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fixe…
- CVE-2026-48750CRITICALCVSS 9.9EG 9.9fixed in 7.2.02026-06-26
Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exe…
- CVE-2026-48751CRITICALCVSS 9.9EG 9.9fixed in 7.2.02026-06-26
Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel…
- CVE-2026-48752CRITICALCVSS 9.9EG 9.9fixed in 7.2.02026-06-26
Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution.…
- CVE-2026-48753CRITICALCVSS 9.9EG 9.9fixed in 7.1.02026-06-26
Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary comm…
- CVE-2026-48754LOWCVSS 2.1EG 2.1fixed in 7.1.02026-06-26
Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).createDependentVolumesFromBackup` in `internal/server/storage/backend.go` contains a cluster of unguarded pointer derefs on every dependent-volume…
- CVE-2026-48755CRITICALCVSS 9.9EG 9.9fixed in 7.2.02026-06-26
Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file…
- CVE-2026-48756LOWCVSS 2.1EG 2.1fixed in 7.1.02026-06-26
Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateCustomVolumeFromBackup` in `internal/server/storage/backend.go` contains an unguarded `*time.Time` dereference on the `ExpiresAt` field of e…
- CVE-2026-48769CRITICALCVSS 9.9EG 9.9fixed in 7.2.02026-06-26
Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary comma…
- CVE-2026-55621HIGHCVSS 7.7EG 7.7fixed in 7.2.02026-08-21
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of a …
- CVE-2026-55622HIGHCVSS 7.7EG 7.7fixed in 7.2.02026-08-21
Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an inst…
Check whether github.com/lxc/incus/v7 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/lxc/incus/v7 CVEs against the assets you own.
Book a Demo →