Lxc Incus vulnerabilities
20 known vulnerabilities affecting lxc/incus.
Total CVEs
20
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH6MEDIUM11LOW1
Vulnerabilities
Page 1 of 1
CVE-2026-33897P2CRITICALCVSS 9.9fixed in 6.23.02026-03-26
CVE-2026-33897 [CRITICAL] CWE-1336 CVE-2026-33897: Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template
Incus is a system container and virtual machine manager. Prior to version 6.23.0, instance template files can be used to cause arbitrary read or writes as root on the host server. Incus allows for pongo2 templates within instances which can be used at various times in the instance lifecycle to template files inside of the instance. This particular
nvdosv
CVE-2026-33945P2CRITICALCVSS 9.6fixed in 6.23.02026-03-27
CVE-2026-33945 [CRITICAL] CWE-22 CVE-2026-33945: Incus is a system container and virtual machine manager. Incus instances have an option to provide c
Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For containers, this is handled through a shared directory. Prior to version 6.23.0, an attacker can set a configuration key named something like `systemd.credential.../../../../../../root/.bashrc` to cause Incus t
nvdosv
CVE-2026-23954P3HIGHCVSS 8.7v>= 6.1.0, <= 6.20.0≤ 6.0.52026-01-22
CVE-2026-23954 [HIGH] CWE-22 CVE-2026-23954: Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with
Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic links in the templating functionality to achieve host arbitrary file read, and host arbitrary file write. This ultimately re
nvdosv
CVE-2026-23953P3HIGHCVSS 8.7v>= 6.1.0, <= 6.20.0≤ 6.0.52026-01-22
CVE-2026-23953 [HIGH] CWE-93 CVE-2026-23953: Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with t
Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a custom YAML configuration (e.g a member of the ‘incus’ group) can create an environment variable containing newlines, which can be used to add additional configuration items in the container’s lxc.conf due to newli
nvdosv
CVE-2026-33898P3HIGHCVSS 8.8fixed in 6.23.02026-03-27
CVE-2026-33898 [HIGH] CWE-287 CVE-2026-33898: Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spa
Incus is a system container and virtual machine manager. Prior to version 6.23.0, the web server spawned by `incus webui` incorrectly validates the authentication token such that an invalid value will be accepted. `incus webui` runs a local web server on a random localhost port. For authentication, it provides the user with a URL containing an authent
nvd
CVE-2026-33711P3HIGHCVSS 7.8fixed in 6.23.02026-03-26
CVE-2026-33711 [HIGH] CWE-61 CVE-2026-33711: Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screen
Incus is a system container and virtual machine manager. Incus provides an API to retrieve VM screenshots. That API relies on the use of a temporary file for QEMU to write the screenshot to which is then picked up and sent to the user prior to deletion. As versions prior to 6.23.0 use predictable paths under /tmp for this, an attacker with local access
nvdosv
CVE-2025-64507P3HIGHCVSS 7.8fixed in 6.0.6v>= 6.1.0, < 6.19.02025-11-10
CVE-2025-64507 [HIGH] CWE-269 CVE-2025-64507: Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.1
Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment where an unprivileged user may have root access to a container with an attached custom storage volume that has the `security.shifted` property set to `true` as well as access to the host as an unprivileged us
nvdosv
CVE-2026-24767P3MEDIUMCVSS 6.4fixed in 7.0.02026-01-28
CVE-2026-24767 [MEDIUM] CWE-918 CVE-2026-24767: NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a blind Server-
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a blind Server-Side Request Forgery (SSRF) vulnerability exists in the `uploadViaURL` functionality due to an unprotected `HEAD` request. While the subsequent file retrieval logic correctly enforces SSRF protections, the initial metadata request executes without val
nvd
CVE-2025-52890P3HIGHCVSS 8.1v>= 6.12, <= 6.132025-06-25
CVE-2025-52890 [HIGH] CWE-863 CVE-2025-52890: Incus is a system container and virtual machine manager. When using an ACL on a device connected to
Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus versions 6.12 and 6.13generates nftables rules that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` and `security.ipv6_filtering`. This can lead to ARP spoofing on the bridge and to fully spoof anothe
nvd
CVE-2026-33743P3MEDIUMCVSS 6.5fixed in 6.23.02026-03-26
CVE-2026-33743 [MEDIUM] CWE-770 CVE-2026-33743: Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafte
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API. This does n
nvdosv
CVE-2026-41684P3MEDIUMCVSS 6.5fixed in 7.0.02026-05-07
CVE-2026-41684 [MEDIUM] CWE-476 CVE-2026-41684: Incus is a system container and virtual machine manager. Prior to version 7.0.0, backup.GetInfo() tr
Incus is a system container and virtual machine manager. Prior to version 7.0.0, backup.GetInfo() trusts the inline backup/index.yaml config when present and only falls back to parsing the legacy backup/container/backup.yaml file if result.Config == nil. As a result, an archive can carry a valid inline config that passes the initial import preflight
nvd
CVE-2026-40251P3MEDIUMCVSS 6.5fixed in 7.0.02026-05-06
CVE-2026-40251 [MEDIUM] CWE-129 CVE-2026-40251: Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validatio
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon to crash. The backup restore subsystem contains an out-of-bounds panic vulnerability caused by an invalid bound
nvd
CVE-2026-40195P3MEDIUMCVSS 6.5fixed in 7.0.02026-05-06
CVE-2026-40195 [MEDIUM] CWE-476 CVE-2026-40195: Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validatio
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage bucket import logic allows an authenticated user with access to the storage bucket feature to cause the Incus daemon to crash. The vulnerability is present in the backup metadata handling logic, where the daemon processes the in
nvd
CVE-2026-40197P3MEDIUMCVSS 6.5fixed in 7.0.02026-05-06
CVE-2026-40197 [MEDIUM] CWE-476 CVE-2026-40197: Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validatio
Incus is a system container and virtual machine manager. In versions before 7.0.0, missing validation logic in the storage volume import logic allows an authenticated user with access to the storage volume feature to cause the Incus daemon to crash. The custom volume backup import subsystem contains a nil-pointer dereference vulnerability during imp
nvd
CVE-2026-41647P3MEDIUMCVSS 6.5fixed in 7.0.02026-05-07
CVE-2026-41647 [MEDIUM] CWE-476 CVE-2026-41647: Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error han
Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an authenticated Incus user to cause a daemon crash through the import of a truncated storage bucket backup file. This issue has been patched in version 7.0.0.
nvd
CVE-2026-41648P4MEDIUMCVSS 5.0fixed in 7.0.02026-05-07
CVE-2026-41648 [MEDIUM] CWE-770 CVE-2026-41648: Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image
Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs would be unpacked and YAML files parsed without any size restrictions. This was making it easy for an authenticated user to provide a crafted image or backup tarball that when parsed by Incus would lead to a very large YAML docume
nvd
CVE-2026-40243P4MEDIUMCVSS 4.8fixed in 7.0.02026-05-06
CVE-2026-40243 [MEDIUM] CWE-295 CVE-2026-40243: Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS valida
Incus is a system container and virtual machine manager. In versions before 7.0.0, broken TLS validation logic in the OVN database connection logic can allow connections to an attacker's OVN database. The OVN client implementations disable Go standard TLS server verification and replace it with custom peer-certificate verification logic. That replac
nvd
CVE-2026-33542P4MEDIUMCVSS 4.8fixed in 6.23.02026-03-26
CVE-2026-33542 [MEDIUM] CWE-295 CVE-2026-33542: Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validati
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a lack of validation of the image fingerprint when downloading from simplestreams image servers opens the door to image cache poisoning and under very narrow circumstances exposes other tenants to running attacker controlled images rather than the expected one. Version
nvdosv
CVE-2026-41685P4MEDIUMCVSS 4.3fixed in 7.0.02026-05-07
CVE-2026-41685 [MEDIUM] CWE-770 CVE-2026-41685: Incus is a system container and virtual machine manager. Prior to version 7.0.0, uploads of large am
Incus is a system container and virtual machine manager. Prior to version 7.0.0, uploads of large amount of data by authenticated users can run the Incus server out of disk space, potentially taking down the host system. The impact here is limited for anyone using storage.images_volume and storage.backups_volume as those users will have large upload
nvd
CVE-2025-52889P4LOWCVSS 3.4v>= 6.12, <= 6.132025-06-25
CVE-2025-52889 [LOW] CWE-770 CVE-2025-52889: Incus is a system container and virtual machine manager. When using an ACL on a device connected to
Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus version 6.12 and 6.13 generates nftables rules for local services (DHCP, DNS...) that partially bypass security options `security.mac_filtering`, `security.ipv4_filtering` and `security.ipv6_filtering`. This can lead to DHCP pool exhaustio
nvd