Search CVE reports


Toggle filters

1 – 10 of 36 results


CVE-2025-58190

Medium priority
Needs evaluation

The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

7 affected packages

golang-golang-x-net, google-guest-agent, containerd, golang-golang-x-net-dev, adsys...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Needs evaluation Needs evaluation
google-guest-agent Needs evaluation Needs evaluation Needs evaluation Needs evaluation
containerd Needs evaluation Needs evaluation Needs evaluation Needs evaluation
golang-golang-x-net-dev Not in release Not in release Needs evaluation Needs evaluation
adsys Needs evaluation Needs evaluation Needs evaluation
juju-core Not in release Not in release
lxd Not in release Not in release Needs evaluation Needs evaluation
Show all 7 packages Show less packages

CVE-2025-47911

Medium priority
Needs evaluation

The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.

7 affected packages

golang-golang-x-net, google-guest-agent, containerd, golang-golang-x-net-dev, adsys...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-golang-x-net Needs evaluation Needs evaluation
google-guest-agent Needs evaluation Needs evaluation Needs evaluation Needs evaluation
containerd Needs evaluation Needs evaluation Needs evaluation Needs evaluation
golang-golang-x-net-dev Not in release Not in release Needs evaluation Needs evaluation
adsys Needs evaluation Needs evaluation Needs evaluation
juju-core Not in release Not in release
lxd Not in release Not in release Needs evaluation Needs evaluation
Show all 7 packages Show less packages

CVE-2026-23954

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. Versions 6.21.0 and below allow a user with the ability to launch a container with a custom image (e.g a member of the ‘incus’ group) to use directory traversal or symbolic...

2 affected packages

incus, lxd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
incus Needs evaluation Not in release
lxd Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-23953

Medium priority
Needs evaluation

Incus is a system container and virtual machine manager. In versions 6.20.0 and below, a user with the ability to launch a container with a custom YAML configuration (e.g a member of the ‘incus’ group) can create an...

2 affected packages

incus, lxd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
incus Needs evaluation Not in release
lxd Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2025-58181

Medium priority

Some fixes available 7 of 23

SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.

4 affected packages

lxd, golang-go.crypto, snapd, google-guest-agent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lxd Not in release Not in release Not affected Needs evaluation
golang-go.crypto Needs evaluation Needs evaluation Needs evaluation Needs evaluation
snapd Needs evaluation Needs evaluation Needs evaluation Needs evaluation
google-guest-agent Fixed Fixed Fixed Fixed
Show less packages

CVE-2025-47914

Medium priority
Needs evaluation

SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.

4 affected packages

golang-go.crypto, snapd, lxd, google-guest-agent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-go.crypto Needs evaluation Needs evaluation Needs evaluation Needs evaluation
snapd Needs evaluation Needs evaluation Needs evaluation Needs evaluation
lxd Not in release Not in release Not affected Needs evaluation
google-guest-agent Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-47913

Medium priority
Needs evaluation

SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process.

4 affected packages

golang-go.crypto, snapd, lxd, google-guest-agent

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
golang-go.crypto Needs evaluation Needs evaluation Needs evaluation Needs evaluation
snapd Needs evaluation Needs evaluation Needs evaluation Needs evaluation
lxd Not in release Not in release Not affected Needs evaluation
google-guest-agent Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-54293

Medium priority
Needs evaluation

Path Traversal in the log file retrieval function in Canonical LXD 5.0 LTS on Linux allows authenticated remote attackers to read arbitrary files on the host system via crafted log file names or symbolic links.

1 affected package

lxd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lxd Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2025-54292

Medium priority
Not affected

Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 on all platforms allows remote authenticated attackers to access or modify unintended resources via crafted resource names embedded in URL paths.

1 affected package

lxd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lxd Not in release Not in release Not affected Not affected
Show less packages

CVE-2025-54291

Medium priority
Not affected

Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code responses.

1 affected package

lxd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lxd Not in release Not in release Not affected Not affected
Show less packages