Executive brief
Non-recursive certificate listing bypasses per-object authorization and leaks all fingerprints in github.com/canonical/lxd
Affected products
- Go github.com/canonical/lxd
Junglewise Threat Intelligence
CVE-2026-3351 · Severity: medium · CVSS 4 · Published 2026-03-10
Technologies: github.com/canonical/lxd (Go). Vendors: Go.
Non-recursive certificate listing bypasses per-object authorization and leaks all fingerprints in github.com/canonical/lxd