Technology · Go
github.com/canonical/lxd (Go) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 14 vulnerabilities in github.com/canonical/lxd (Go): 0 in the last 7 days and 0 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-34177, was published on 10 April 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 3
- Exploited in the wild
- 0
About github.com/canonical/lxd (Go)
A system container and virtual machine manager for Linux.
Latest github.com/canonical/lxd (Go) vulnerabilities
- CVE-2026-34177: Canonical LXD VM restriction bypass in isVMLowLevelOptionForbiddencriticalCVSS 9.1EPSS 0.6%
- CVE-2026-34178: Canonical LXD project restriction bypass via crafted backup importcriticalCVSS 9.1EPSS 0.7%
- CVE-2026-34179: Canonical LXD privilege escalation via certificate type modificationcriticalCVSS 9.1EPSS 0.4%
- CVE-2026-3351: GO-2026-4595 - Non-recursive certificate listing bypasses per-object authorization and leaks all fingerprints in…mediumCVSS 4EPSS 0.2%
- GO-2025-4121 - LXD vulnerable to a local privilege escalation through custom storage volumes in lxd in github.com/canonical/lxdinfo
- LXD vulnerable to a local privilege escalation through custom storage volumesmediumCVSS 4
- CVE-2025-54288: GO-2025-4001 - Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server in…lowCVSS 3.1EPSS 0.4%
- CVE-2025-54289: GO-2025-3999 - Privilege Escalation via WebSocket Connection Hijacking in Operations API in github.com/canonical/lxdlowCVSS 3.1EPSS 0.2%
- CVE-2025-54293: GO-2025-4000 - Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function in…lowCVSS 3.1EPSS 0.6%
- CVE-2025-54291: GO-2025-4005 - Canonical LXD Project Existence Determination Through Error Handling in Image Get Function in…lowCVSS 3.1EPSS 0.4%
- CVE-2025-54286: GO-2025-4003 - CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI in github.com/canonical/lxdlowCVSS 3.1EPSS 0.1%
- CVE-2025-54290: GO-2025-4002 - Canonical LXD Project Existence Determination Through Error Handling in Image Export Function in…mediumCVSS 4EPSS 0.3%
- CVE-2024-6219: Canonical LXD privilege escalation in PKI mode TLS certificateslowCVSS 3.8EPSS 0.2%
- CVE-2024-6156: GO-2024-3312 - CA certificate sign check bypass in github.com/canonical/lxdlowCVSS 3.1EPSS 0.2%
Most severe github.com/canonical/lxd (Go) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-34178: Canonical LXD project restriction bypass via crafted backup importcriticalCVSS 9.1EPSS 0.7%
- CVE-2026-34177: Canonical LXD VM restriction bypass in isVMLowLevelOptionForbiddencriticalCVSS 9.1EPSS 0.6%
- CVE-2026-34179: Canonical LXD privilege escalation via certificate type modificationcriticalCVSS 9.1EPSS 0.4%
- CVE-2025-54290: GO-2025-4002 - Canonical LXD Project Existence Determination Through Error Handling in Image Export Function in…mediumCVSS 4EPSS 0.3%
- CVE-2026-3351: GO-2026-4595 - Non-recursive certificate listing bypasses per-object authorization and leaks all fingerprints in…mediumCVSS 4EPSS 0.2%
- LXD vulnerable to a local privilege escalation through custom storage volumesmediumCVSS 4
- CVE-2024-6219: Canonical LXD privilege escalation in PKI mode TLS certificateslowCVSS 3.8EPSS 0.2%
- CVE-2025-54293: GO-2025-4000 - Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function in…lowCVSS 3.1EPSS 0.6%
- CVE-2025-54291: GO-2025-4005 - Canonical LXD Project Existence Determination Through Error Handling in Image Get Function in…lowCVSS 3.1EPSS 0.4%
- CVE-2025-54288: GO-2025-4001 - Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server in…lowCVSS 3.1EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/github-com-canonical-lxd.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "github.com/canonical/lxd (Go) vulnerabilities", https://junglewise.ai/threats/technologies/github-com-canonical-lxd, 26 September 2026.