go

github.com/canonical/lxd

View on go registry
27 Total advisories
27 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/canonical/lxd is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 5.3
Go

CVE-2025-54291

Canonical LXD Project Existence Determination Through Error Handling in Image Get Function

UNKNOWN
Go

CVE-2025-54290

Canonical LXD Project Existence Determination Through Error Handling in Image Export Function

HIGH 8.3
Go

CVE-2025-54286

Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI

MEDIUM 4.1
Go

CVE-2025-54288

Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server

MEDIUM 6.5
Go

CVE-2025-54293

Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function

MEDIUM 6.8
Go

CVE-2025-54289

Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API

CRITICAL 9.1
Go

CVE-2026-34177

LXD: VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf

CRITICAL 9.1
Go

CVE-2026-34178

LXD: Importing a crafted backup leads to project restriction bypass

CRITICAL 9.1
Go

CVE-2026-34179

LXD: Update of type field in restricted TLS certificate allows privilege escalation to cluster admin

UNKNOWN
Go

CVE-2026-34179

Type field in restricted TLS certificate allows privilege escalation in github.com/canonical/lxd

UNKNOWN
Go

CVE-2026-34177

VM lowlevel restriction bypass via raw.apparmor and raw.qemu.conf in github.com/canonical/lxd

UNKNOWN
Go

CVE-2026-34178

LXD: Importing a crafted backup leads to project restriction bypass in github.com/canonical/lxd

LOW 3.8
Go

CVE-2024-6219

lxd has a restricted TLS certificate privilege escalation when in PKI mode

UNKNOWN
Go

CVE-2026-3351

lxd's non-recursive certificate listing bypasses per-object authorization and leaks all fingerprints

UNKNOWN
Go

CVE-2026-3351

Non-recursive certificate listing bypasses per-object authorization and leaks all fingerprints in github.com/canonical/lxd

UNKNOWN
Go

GO-2025-4121

LXD vulnerable to a local privilege escalation through custom storage volumes

UNKNOWN
Go

GHSA-3g2j-vm47-x4mj

LXD vulnerable to a local privilege escalation through custom storage volumes in lxd in github.com/canonical/lxd

UNKNOWN
Go

CVE-2025-54286

CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI in github.com/canonical/lxd

UNKNOWN
Go

CVE-2025-54289

Privilege Escalation via WebSocket Connection Hijacking in Operations API in github.com/canonical/lxd

UNKNOWN
Go

CVE-2025-54291

Canonical LXD Project Existence Determination Through Error Handling in Image Get Function in github.com/canonical/lxd

UNKNOWN
Go

CVE-2025-54293

Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function in github.com/canonical/lxd

UNKNOWN
Go

CVE-2025-54288

Canonical LXD Source Container Identification Vulnerability via cmdline Spoofing in devLXD Server in github.com/canonical/lxd

UNKNOWN
Go

CVE-2025-54290

Canonical LXD Project Existence Determination Through Error Handling in Image Export Function in github.com/canonical/lxd

UNKNOWN
Go

GHSA-x9qq-236j-gj97

Canonical LXD documentation improvement to make clear restricted.devices.disk=allow without restricted.devices.disk.paths also allows shift=true

LOW 3.8
Go

CVE-2024-6156

lxd CA certificate sign check bypass

UNKNOWN
Go

CVE-2024-6219

Restricted TLS certificate privilege escalation when in PKI mode in github.com/canonical/lxd

UNKNOWN
Go

CVE-2024-6156

CA certificate sign check bypass in github.com/canonical/lxd

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes