{"schema_version":1,"title":"github.com/canonical/lxd (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 14 vulnerabilities in github.com/canonical/lxd (Go): 0 in the last 7 days and 0 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-34177, was published on 10 April 2026.","url":"https://junglewise.ai/threats/technologies/github-com-canonical-lxd","json_url":"https://junglewise.ai/threats/technologies/github-com-canonical-lxd.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/github-com-canonical-lxd","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":14,"critical":3,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":12},"latest":[{"cve":"CVE-2026-34177","cvss":9.1,"epss":0.0061,"slug":"cve-2026-34177-canonical-lxd-vm-restriction-bypass-in","title":"Canonical LXD VM restriction bypass in isVMLowLevelOptionForbidden","severity":"critical","exploited":false,"published_at":"2026-04-10T19:21:00+00:00","url":"https://junglewise.ai/threats/cve-2026-34177-canonical-lxd-vm-restriction-bypass-in"},{"cve":"CVE-2026-34178","cvss":9.1,"epss":0.0068,"slug":"cve-2026-34178-canonical-lxd-project-restriction-bypass-via-crafted-backup","title":"Canonical LXD project restriction bypass via crafted backup import","severity":"critical","exploited":false,"published_at":"2026-04-10T19:20:55+00:00","url":"https://junglewise.ai/threats/cve-2026-34178-canonical-lxd-project-restriction-bypass-via-crafted-backup"},{"cve":"CVE-2026-34179","cvss":9.1,"epss":0.0042,"slug":"cve-2026-34179-canonical-lxd-privilege-escalation-via-certificate-type","title":"Canonical LXD privilege escalation via certificate type modification","severity":"critical","exploited":false,"published_at":"2026-04-10T19:20:50+00:00","url":"https://junglewise.ai/threats/cve-2026-34179-canonical-lxd-privilege-escalation-via-certificate-type"},{"cve":"CVE-2026-3351","cvss":4,"epss":0.0021,"slug":"cve-2026-3351-lxd-s-non-recursive-certificate-listing-bypasses-per-object","title":"GO-2026-4595 - Non-recursive certificate listing bypasses per-object authorization and leaks all fingerprints in github.com/canonical/lxd","severity":"medium","exploited":false,"published_at":"2026-03-10T18:28:25+00:00","url":"https://junglewise.ai/threats/cve-2026-3351-lxd-s-non-recursive-certificate-listing-bypasses-per-object"},{"slug":"go-2025-4121-lxd-vulnerable-to-a-local-privilege-escalation-through-8fc51dbc","title":"GO-2025-4121 - LXD vulnerable to a local privilege escalation through custom storage volumes in lxd in github.com/canonical/lxd","severity":"info","exploited":false,"published_at":"2025-11-18T15:44:15+00:00","url":"https://junglewise.ai/threats/go-2025-4121-lxd-vulnerable-to-a-local-privilege-escalation-through-8fc51dbc"},{"cvss":4,"slug":"lxd-vulnerable-to-a-local-privilege-escalation-through-custom-storage-712b2107","title":"LXD vulnerable to a local privilege escalation through custom storage volumes","severity":"medium","exploited":false,"published_at":"2025-11-13T23:01:44+00:00","url":"https://junglewise.ai/threats/lxd-vulnerable-to-a-local-privilege-escalation-through-custom-storage-712b2107"},{"cve":"CVE-2025-54288","cvss":3.1,"epss":0.0035,"slug":"cve-2025-54288-canonical-lxd-source-container-identification-vulnerability-via","title":"GO-2025-4001 - Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server in github.com/canonical/lxd","severity":"low","exploited":false,"published_at":"2025-11-05T18:41:07+00:00","url":"https://junglewise.ai/threats/cve-2025-54288-canonical-lxd-source-container-identification-vulnerability-via"},{"cve":"CVE-2025-54289","cvss":3.1,"epss":0.0021,"slug":"cve-2025-54289-canonical-lxd-vulnerable-to-privilege-escalation-via-websocket","title":"GO-2025-3999 - Privilege Escalation via WebSocket Connection Hijacking in Operations API in github.com/canonical/lxd","severity":"low","exploited":false,"published_at":"2025-11-05T18:41:07+00:00","url":"https://junglewise.ai/threats/cve-2025-54289-canonical-lxd-vulnerable-to-privilege-escalation-via-websocket"},{"cve":"CVE-2025-54293","cvss":3.1,"epss":0.0058,"slug":"cve-2025-54293-canonical-lxd-path-traversal-vulnerability-in-instance-log-file","title":"GO-2025-4000 - Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function in github.com/canonical/lxd","severity":"low","exploited":false,"published_at":"2025-11-05T18:41:07+00:00","url":"https://junglewise.ai/threats/cve-2025-54293-canonical-lxd-path-traversal-vulnerability-in-instance-log-file"},{"cve":"CVE-2025-54291","cvss":3.1,"epss":0.0039,"slug":"cve-2025-54291-canonical-lxd-project-existence-determination-through-error","title":"GO-2025-4005 - Canonical LXD Project Existence Determination Through Error Handling in Image Get Function in github.com/canonical/lxd","severity":"low","exploited":false,"published_at":"2025-11-05T18:41:07+00:00","url":"https://junglewise.ai/threats/cve-2025-54291-canonical-lxd-project-existence-determination-through-error"},{"cve":"CVE-2025-54286","cvss":3.1,"epss":0.0013,"slug":"cve-2025-54286-canonical-lxd-csrf-vulnerability-when-using-client-certificate","title":"GO-2025-4003 - CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI in github.com/canonical/lxd","severity":"low","exploited":false,"published_at":"2025-11-05T18:41:07+00:00","url":"https://junglewise.ai/threats/cve-2025-54286-canonical-lxd-csrf-vulnerability-when-using-client-certificate"},{"cve":"CVE-2025-54290","cvss":4,"epss":0.0034,"slug":"cve-2025-54290-canonical-lxd-project-existence-determination-through-error","title":"GO-2025-4002 - Canonical LXD Project Existence Determination Through Error Handling in Image Export Function in github.com/canonical/lxd","severity":"medium","exploited":false,"published_at":"2025-11-05T18:41:07+00:00","url":"https://junglewise.ai/threats/cve-2025-54290-canonical-lxd-project-existence-determination-through-error"},{"cve":"CVE-2024-6219","cvss":3.8,"epss":0.0016,"slug":"cve-2024-6219-canonical-lxd-privilege-escalation-in-pki-mode-tls-certificates","title":"Canonical LXD privilege escalation in PKI mode TLS certificates","severity":"low","exploited":false,"published_at":"2024-12-09T22:43:13+00:00","url":"https://junglewise.ai/threats/cve-2024-6219-canonical-lxd-privilege-escalation-in-pki-mode-tls-certificates"},{"cve":"CVE-2024-6156","cvss":3.1,"epss":0.0016,"slug":"cve-2024-6156-lxd-ca-certificate-sign-check-bypass","title":"GO-2024-3312 - CA certificate sign check bypass in github.com/canonical/lxd","severity":"low","exploited":false,"published_at":"2024-12-09T18:32:51+00:00","url":"https://junglewise.ai/threats/cve-2024-6156-lxd-ca-certificate-sign-check-bypass"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"github.com/rclone/rclone (Go)","slug":"github-com-rclone-rclone","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/github-com-rclone-rclone"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/filebrowser/filebrowser/v2 (Go)","slug":"github-com-filebrowser-filebrowser-v2","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-filebrowser-filebrowser-v2"},{"name":"github.com/fission/fission (Go)","slug":"github-com-fission-fission","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-fission-fission"},{"name":"github.com/klever-io/klever-go (Go)","slug":"github-com-klever-io-klever-go","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-klever-io-klever-go"},{"name":"code.vikunja.io/api (Go)","slug":"code-vikunja-io-api","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/code-vikunja-io-api"},{"name":"github.com/cloudreve/Cloudreve/v4 (Go)","slug":"github-com-cloudreve-cloudreve-v4","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/github-com-cloudreve-cloudreve-v4"},{"name":"github.com/gotenberg/gotenberg/v8 (Go)","slug":"github-com-gotenberg-gotenberg-v8","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v8"},{"name":"github.com/nezhahq/nezha (Go)","slug":"github-com-nezhahq-nezha","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-nezhahq-nezha"},{"name":"github.com/fleetdm/fleet/v4 (Go)","slug":"github-com-fleetdm-fleet-v4","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/github-com-fleetdm-fleet-v4"}],"technology":{"hub":true,"name":"github.com/canonical/lxd (Go)","slug":"github-com-canonical-lxd","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"homepage":"https://linuxcontainers.org/lxd/","repo_url":"https://github.com/canonical/lxd","description":"A system container and virtual machine manager for Linux.","url":"https://junglewise.ai/threats/technologies/github-com-canonical-lxd"},"most_severe":[{"cve":"CVE-2026-34178","cvss":9.1,"epss":0.0068,"slug":"cve-2026-34178-canonical-lxd-project-restriction-bypass-via-crafted-backup","title":"Canonical LXD project restriction bypass via crafted backup import","severity":"critical","exploited":false,"published_at":"2026-04-10T19:20:55+00:00","url":"https://junglewise.ai/threats/cve-2026-34178-canonical-lxd-project-restriction-bypass-via-crafted-backup"},{"cve":"CVE-2026-34177","cvss":9.1,"epss":0.0061,"slug":"cve-2026-34177-canonical-lxd-vm-restriction-bypass-in","title":"Canonical LXD VM restriction bypass in isVMLowLevelOptionForbidden","severity":"critical","exploited":false,"published_at":"2026-04-10T19:21:00+00:00","url":"https://junglewise.ai/threats/cve-2026-34177-canonical-lxd-vm-restriction-bypass-in"},{"cve":"CVE-2026-34179","cvss":9.1,"epss":0.0042,"slug":"cve-2026-34179-canonical-lxd-privilege-escalation-via-certificate-type","title":"Canonical LXD privilege escalation via certificate type modification","severity":"critical","exploited":false,"published_at":"2026-04-10T19:20:50+00:00","url":"https://junglewise.ai/threats/cve-2026-34179-canonical-lxd-privilege-escalation-via-certificate-type"},{"cve":"CVE-2025-54290","cvss":4,"epss":0.0034,"slug":"cve-2025-54290-canonical-lxd-project-existence-determination-through-error","title":"GO-2025-4002 - Canonical LXD Project Existence Determination Through Error Handling in Image Export Function in github.com/canonical/lxd","severity":"medium","exploited":false,"published_at":"2025-11-05T18:41:07+00:00","url":"https://junglewise.ai/threats/cve-2025-54290-canonical-lxd-project-existence-determination-through-error"},{"cve":"CVE-2026-3351","cvss":4,"epss":0.0021,"slug":"cve-2026-3351-lxd-s-non-recursive-certificate-listing-bypasses-per-object","title":"GO-2026-4595 - Non-recursive certificate listing bypasses per-object authorization and leaks all fingerprints in github.com/canonical/lxd","severity":"medium","exploited":false,"published_at":"2026-03-10T18:28:25+00:00","url":"https://junglewise.ai/threats/cve-2026-3351-lxd-s-non-recursive-certificate-listing-bypasses-per-object"},{"cvss":4,"slug":"lxd-vulnerable-to-a-local-privilege-escalation-through-custom-storage-712b2107","title":"LXD vulnerable to a local privilege escalation through custom storage volumes","severity":"medium","exploited":false,"published_at":"2025-11-13T23:01:44+00:00","url":"https://junglewise.ai/threats/lxd-vulnerable-to-a-local-privilege-escalation-through-custom-storage-712b2107"},{"cve":"CVE-2024-6219","cvss":3.8,"epss":0.0016,"slug":"cve-2024-6219-canonical-lxd-privilege-escalation-in-pki-mode-tls-certificates","title":"Canonical LXD privilege escalation in PKI mode TLS certificates","severity":"low","exploited":false,"published_at":"2024-12-09T22:43:13+00:00","url":"https://junglewise.ai/threats/cve-2024-6219-canonical-lxd-privilege-escalation-in-pki-mode-tls-certificates"},{"cve":"CVE-2025-54293","cvss":3.1,"epss":0.0058,"slug":"cve-2025-54293-canonical-lxd-path-traversal-vulnerability-in-instance-log-file","title":"GO-2025-4000 - Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function in github.com/canonical/lxd","severity":"low","exploited":false,"published_at":"2025-11-05T18:41:07+00:00","url":"https://junglewise.ai/threats/cve-2025-54293-canonical-lxd-path-traversal-vulnerability-in-instance-log-file"},{"cve":"CVE-2025-54291","cvss":3.1,"epss":0.0039,"slug":"cve-2025-54291-canonical-lxd-project-existence-determination-through-error","title":"GO-2025-4005 - Canonical LXD Project Existence Determination Through Error Handling in Image Get Function in github.com/canonical/lxd","severity":"low","exploited":false,"published_at":"2025-11-05T18:41:07+00:00","url":"https://junglewise.ai/threats/cve-2025-54291-canonical-lxd-project-existence-determination-through-error"},{"cve":"CVE-2025-54288","cvss":3.1,"epss":0.0035,"slug":"cve-2025-54288-canonical-lxd-source-container-identification-vulnerability-via","title":"GO-2025-4001 - Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server in github.com/canonical/lxd","severity":"low","exploited":false,"published_at":"2025-11-05T18:41:07+00:00","url":"https://junglewise.ai/threats/cve-2025-54288-canonical-lxd-source-container-identification-vulnerability-via"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}