Known vulnerabilities in LXD

Software: LXD
Software CPE: cpe:2.3:a:linux_containers:lxd:*:*:*:*:*:*:*:*
Total vulnerabilities: 48
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.7

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting LXD LXD is affected by 48 known vulnerabilities: 25 medium, 23 low Critical High Medium Low

Vulnerabilities (48)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU152256 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-86334
CWE-22 Low
No
No
4.0.14, 5.0.10, 5.21.8, 6.10 25.09.2026 SB20260925261
#VU152255 - Missing Authorization
CVE-2026-86335
CWE-862 Low
No
No
5.0.10, 5.21.8, 6.10 25.09.2026 SB20260925261
#VU152254 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-85526
CWE-22 Medium
No
No
4.0.14, 5.0.10, 5.21.8, 6.10 25.09.2026 SB20260925261
#VU152253 - Relative Path Traversal
CVE-2026-85185
CWE-23 Medium
No
No
4.0.14, 5.0.10, 5.21.8, 6.10 25.09.2026 SB20260925261
#VU152252 - Missing Authorization
CVE-2026-97335
CWE-862 Low
No
No
5.0.10, 5.21.8, 6.10 25.09.2026 SB20260925261
#VU152251 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-87799
CWE-59 Medium
No
No
4.0.14, 5.0.10, 5.21.8, 6.10 25.09.2026 SB20260925261
#VU152250 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-87798
CWE-59 Low
No
No
4.0.14, 5.0.10, 5.21.8 25.09.2026 SB20260925261
#VU145363 - Relative Path Traversal
CVE-2026-66897
CWE-23 Medium
No
No
4.0.13, 5.0.9, 5.21.7, 6.10 25.08.2026 SB20260825137
#VU140683 - Missing Authorization
CVE-2026-63300
CWE-862 Medium
No
No
5.0.8, 5.21.6, 6.10 01.08.2026 SB2026080112
#VU140682 - Incorrect Authorization
CVE-2026-62420
CWE-863 Medium
No
No
5.0.8, 5.21.6, 6.10 01.08.2026 SB2026080112
#VU140681 - Allocation of Resources Without Limits or Throttling
CVE-2026-63299
CWE-770 Medium
No
No
5.0.8, 5.21.6, 6.10 01.08.2026 SB2026080112
#VU140680 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-63298
CWE-74 Medium
No
No
4.0.12, 5.0.8, 5.21.6 01.08.2026 SB2026080112
#VU140679 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-63297
CWE-367 Medium
No
No
5.0.8, 5.21.6 01.08.2026 SB2026080112
#VU140678 - Improper Access Control
CVE-2026-63296
CWE-284 Medium
No
No
5.0.8, 5.21.6, 6.10 01.08.2026 SB2026080112
#VU140677 - Improper Access Control
CVE-2026-63295
CWE-284 Low
No
No
4.0.12, 5.0.8, 5.21.6, 6.10 01.08.2026 SB2026080112
#VU140676 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-63294
CWE-59 Medium
No
No
4.0.12, 5.0.8, 5.21.6, 6.10 01.08.2026 SB2026080112
#VU140675 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-63293
CWE-59 Medium
No
No
4.0.12, 5.0.8, 5.21.6, 6.10 01.08.2026 SB2026080112
#VU140674 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-16033
CWE-22 Medium
No
No
5.0.8 01.08.2026 SB2026080112
#VU140673 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-66898
CWE-22 Medium
No
No
4.0.12, 5.0.4, 5.21.2, 6.1 01.08.2026 SB2026080112
#VU135807 - Server-Side Request Forgery (SSRF)
CVE-2026-28385
CWE-918 Low
No
No
6.10 29.06.2026 SB2026063043


Showing elements 1 - 20 out of 48