PT-2026-52849 · Canonical · Lxd

·

CVE-2026-28385

·

Published

2026-06-26

·

Updated

2026-07-06

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Canonical LXD versions 4.12 through 6.9
Description A Server-Side Request Forgery (SSRF) issue exists in the image import functionality. Authenticated users possessing the can create images entitlement can interact with internal network infrastructure through the '/images' endpoint. The LXD daemon does not validate or restrict outbound destination IP addresses when importing an image from a URL source, permitting connections to loopback, RFC1918 private ranges, and cloud metadata endpoints. This allows for unauthorized interaction with internal HTTP services and error-based port scanning from the network position of the daemon.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28385
GHSA-3GQ2-X4QG-P4G6

Affected Products

Lxd