VulnSea

lxc has 14 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 13 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 12. The median CVSS is 9.9 (critical), with 7 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-73 (4) and CWE-476 (3). Most affected products: github.com/lxc/incus/v7/cmd/incusd (10), github.com/lxc/incus/v7 (2), github.com/lxc/lxd (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.9
Publish → KEV
Last 90 days
13 prev 0

Products

  • github.com/lxc/incus/v7/cmd/incusd 10
  • github.com/lxc/incus/v7 2
  • github.com/lxc/lxd 1
  • lxc-ci 1
14
Total CVEs
7
Critical
0
CISA KEV
0
Exploited

lxc vulnerabilities

CVEs affecting lxc, newest first. Open any entry for full detail, references, and exploit status.

14 CVEsRSS

CVE-2026-52727High· 7.2
5d ago

lxc-ci contains continuous integration and image-build scripts for LXC

lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images/archlinux.yaml retain the same pacman local-signing private key in /etc/pacman.d/gnupg…

Twilightlxc · lxc-ciEPSS 0.33%via NVD
CVE-2026-55621High· 7.7
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where an attacker knowing the name of a project that they don't have access to and the name of …

Twilightlxc · github.com/lxc/incus/v7EPSS 0.20%via NVD
CVE-2026-55622High· 7.7
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an attacker knowing the name of a project that they don't have access to and the name of an in…

Twilightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.25%via NVD
CVE-2026-47753Medium
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateInstanceFromBackup` in `internal/server/storage/backend.go` contains a nil-pointer dereference that an authenticated user with permission …

Sunlitlxc · github.com/lxc/incus/v7EPSS 0.26%via NVD
CVE-2026-48749Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fi…

Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.99%via NVD
CVE-2026-48750Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `e…

Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.78%via NVD
CVE-2026-48751Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlev…

Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.86%via NVD
CVE-2026-48752Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command executio…

Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.81%via NVD
CVE-2026-48753Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary co…

Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.87%via NVD
CVE-2026-48754Low
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).createDependentVolumesFromBackup` in `internal/server/storage/backend.go` contains a cluster of unguarded pointer derefs on every dependent-volu…

Sunlitlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.28%via NVD
CVE-2026-48755Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary fi…

Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.44%via NVD
CVE-2026-48756Low
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.1.0, `(*backend).CreateCustomVolumeFromBackup` in `internal/server/storage/backend.go` contains an unguarded `*time.Time` dereference on the `ExpiresAt` field of…

Sunlitlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.23%via NVD
CVE-2026-48769Critical· 9.9
1mo ago

Incus is a system container and virtual machine manager

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary com…

Midnightlxc · github.com/lxc/incus/v7/cmd/incusdEPSS 0.54%via NVD
CVE-2025-54287Medium· 6.5
11mo ago

Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns

Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns

Sunlitlxc · github.com/lxc/lxdEPSS 0.37%via OSV
lxc vulnerabilities (CVEs) · VulnSea