{"api_version":"v1","generated_at":"2026-10-09T08:05:00+00:00","product":{"cve_count":29,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-canonical-lxd-fe6307b9b760","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/lxd","name":"LXD","next_cursor":null,"observations":[{"affected":"LXD: 4.0.2 < 4.0.14, 5.0.0 < 5.0.10, 5.21.0 < 5.21.8, 6.0 < 6.9","affected_versions_present":true,"cve_id":"CVE-2026-87798","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-87798","fixed":"Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8 or later.","last_modified":"2026-09-28T16:32:28.148Z","patch_url":"https://github.com/canonical/lxd/security/advisories/GHSA-mr8v-hx34-hfvf","primary_source":"","published":"2026-09-28T13:22:36.561Z"},{"affected":"LXD: 4.0.0 < 4.0.14, 5.0.0 < 5.0.10, 5.21.0 < 5.21.8, 6.0 < 6.10","affected_versions_present":true,"cve_id":"CVE-2026-87799","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-87799","fixed":"Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later.","last_modified":"2026-09-29T03:55:19.115Z","patch_url":"https://github.com/canonical/lxd/security/advisories/GHSA-fmc3-3cpq-6whr","primary_source":"","published":"2026-09-28T13:22:29.148Z"},{"affected":"LXD: 5.0.0 < 5.0.10, 5.21.0 < 5.21.8, 6.0 < 6.10","affected_versions_present":true,"cve_id":"CVE-2026-97335","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-97335","fixed":"Upgrade to LXD versions 5.0.10, 5.21.8, 6.10 or later.","last_modified":"2026-09-28T16:32:28.403Z","patch_url":"https://github.com/canonical/lxd/security/advisories/GHSA-p456-92fx-44xh","primary_source":"","published":"2026-09-28T13:22:19.371Z"},{"affected":"LXD: 4.0.2 < 4.0.14, 5.0.0 < 5.0.10, 5.21.0 < 5.21.8, 6.0 < 6.10","affected_versions_present":true,"cve_id":"CVE-2026-85185","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-85185","fixed":"Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later.","last_modified":"2026-09-28T16:32:28.529Z","patch_url":"https://github.com/canonical/lxd/security/advisories/GHSA-27q7-qwhm-c34p","primary_source":"","published":"2026-09-28T13:21:51.596Z"},{"affected":"LXD: 4.0.0 < 4.0.14, 5.0.0 < 5.0.10, 5.21.0 < 5.21.8, 6.0 < 6.10","affected_versions_present":true,"cve_id":"CVE-2026-85526","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-85526","fixed":"Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later.","last_modified":"2026-09-29T03:55:18.376Z","patch_url":"https://github.com/canonical/lxd/security/advisories/GHSA-h85r-gjgx-g2rv","primary_source":"","published":"2026-09-28T13:21:40.621Z"},{"affected":"LXD: 5.21.0 < 5.21.8, 6.0 < 6.10, 4.0 < 5.0.10","affected_versions_present":true,"cve_id":"CVE-2026-86335","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86335","fixed":"Upgrade to LXD versions 5.0.10, 5.21.8, 6.10 or later.","last_modified":"2026-09-28T16:32:28.655Z","patch_url":"https://github.com/canonical/lxd/security/advisories/GHSA-j7p3-5g2v-69j8","primary_source":"","published":"2026-09-28T13:21:29.891Z"},{"affected":"LXD: 4.0.2 < 4.0.14, 5.0.0 < 5.0.10, 5.21.0 < 5.21.8, 6.0 < 6.10","affected_versions_present":true,"cve_id":"CVE-2026-86334","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86334","fixed":"Upgrade to LXD versions 4.0.14, 5.0.10, 5.21.8, 6.10 or later.","last_modified":"2026-09-28T17:56:11.126Z","patch_url":"https://github.com/canonical/lxd/security/advisories/GHSA-g4cm-f533-78hq","primary_source":"","published":"2026-09-28T13:21:15.612Z"},{"affected":"4.0.0 < 4.0.13; 5.0.0 < 5.0.9; 5.21.0 < 5.21.7; 6.0 < 6.10","affected_versions_present":true,"cve_id":"CVE-2026-66897","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-66897","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-25T03:55:49.930Z","patch_url":"","primary_source":"","published":"2026-08-24T09:08:04.188Z"},{"affected":"LXD: 4.0.0 < 4.0.12, 5.0.0 < 5.0.8","affected_versions_present":true,"cve_id":"CVE-2026-16033","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-16033","fixed":"Upgrade to LXD version 4.0.12 or later, or 5.0.8 or later.","last_modified":"2026-08-13T12:46:08.117Z","patch_url":"https://github.com/canonical/lxd/security/advisories/GHSA-9hcm-hxh5-7xxh","primary_source":"","published":"2026-08-12T20:11:08.781Z"},{"affected":"4.0.0 < 4.0.12; 5.0.0 < 5.0.4; 5.21.0 < 5.21.2; 6.0 < 6.1","affected_versions_present":true,"cve_id":"CVE-2026-66898","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-66898","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-13T13:40:18.070Z","patch_url":"https://github.com/canonical/lxd/security/advisories/GHSA-m857-c7gc-c984","primary_source":"","published":"2026-08-12T20:07:32.889Z"},{"affected":"4.0.0 < 4.0.12; 5.0.0 < 5.0.8; 5.21.0 < 5.21.6; 6.0 < 6.10","affected_versions_present":true,"cve_id":"CVE-2026-63293","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63293","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-13T12:40:35.947Z","patch_url":"","primary_source":"","published":"2026-08-12T20:00:09.214Z"},{"affected":"4.0.0 < 4.0.12; 5.0.0 < 5.0.8; 5.21.0 < 5.21.6; 6.0 < 6.10","affected_versions_present":true,"cve_id":"CVE-2026-63294","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63294","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-13T12:38:48.134Z","patch_url":"https://github.com/canonical/lxd/security/advisories/GHSA-fv82-v4fj-mm4m","primary_source":"","published":"2026-08-12T19:57:07.898Z"},{"affected":"4.0.0 < 4.0.12; 5.0.0 < 5.0.8; 5.21.0 < 5.21.6; 6.0 < 6.10","affected_versions_present":true,"cve_id":"CVE-2026-63295","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63295","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-13T14:24:15.556Z","patch_url":"","primary_source":"","published":"2026-08-12T19:31:32.323Z"},{"affected":"5.0.0 < 5.0.8; 5.21.0 < 5.21.6; 6.0 < 6.10","affected_versions_present":true,"cve_id":"CVE-2026-63296","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63296","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-13T14:25:39.478Z","patch_url":"https://github.com/canonical/lxd/security/advisories/GHSA-gcr9-5q6r-w625","primary_source":"","published":"2026-08-12T19:27:45.736Z"},{"affected":"5.0.0 < 5.0.8; 5.21.0 < 5.21.6","affected_versions_present":true,"cve_id":"CVE-2026-63297","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63297","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-13T14:29:39.772Z","patch_url":"https://github.com/canonical/lxd/security/advisories/GHSA-v989-qw7w-xvg4","primary_source":"","published":"2026-08-12T19:25:24.420Z"},{"affected":"5.0.0 < 5.0.8; 5.21.0 < 5.21.6; 4.0.0 < 4.0.12","affected_versions_present":true,"cve_id":"CVE-2026-63298","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63298","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-13T14:33:57.467Z","patch_url":"https://github.com/canonical/lxd/security/advisories/GHSA-vfh7-q59q-54v2","primary_source":"","published":"2026-08-12T19:22:07.286Z"},{"affected":"5.0.0 < 5.0.8; 5.21.0 < 5.21.6; 6.0 < 6.10","affected_versions_present":true,"cve_id":"CVE-2026-63299","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63299","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-12T19:26:28.110Z","patch_url":"https://github.com/canonical/lxd/security/advisories/GHSA-5h78-p252-989h","primary_source":"","published":"2026-08-12T19:17:07.418Z"},{"affected":"5.0.0 < 5.0.8; 5.21.0 < 5.21.6; 6.0 < 6.10","affected_versions_present":true,"cve_id":"CVE-2026-62420","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62420","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-08-12T19:27:44.371Z","patch_url":"https://github.com/canonical/lxd/pull/18651","primary_source":"","published":"2026-08-12T19:12:28.097Z"},{"affected":"5.0.0 < 5.0.8; 5.21.0 < 5.21.6; 6.0 < 6.10","affected_versions_present":true,"cve_id":"CVE-2026-63300","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63300","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-08-13T13:19:51.113Z","patch_url":"https://github.com/canonical/lxd/pull/18651","primary_source":"","published":"2026-08-12T19:09:04.445Z"},{"affected":"6.0 < 6.10","affected_versions_present":true,"cve_id":"CVE-2026-28385","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28385","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-26T17:13:58.172Z","patch_url":"https://github.com/canonical/lxd/pull/18462","primary_source":"","published":"2026-06-26T16:23:56.456Z"},{"affected":"5.21.0 < 5.21.5; 5.0.0 < 5.0.7; 6.0 < 6.9","affected_versions_present":true,"cve_id":"CVE-2026-9640","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-9640","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-30T03:55:24.628Z","patch_url":"https://github.com/canonical/lxd/pull/18301","primary_source":"","published":"2026-06-26T15:50:38.453Z"},{"affected":"5.21.0 < 5.21.5; 6.0 < 6.9","affected_versions_present":true,"cve_id":"CVE-2026-9639","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-9639","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-26T16:02:11.520Z","patch_url":"https://github.com/canonical/lxd/security/advisories/GHSA-j93m-3j9p-m5m8","primary_source":"","published":"2026-06-26T15:39:04.696Z"},{"affected":"6.6 < 6.9","affected_versions_present":true,"cve_id":"CVE-2026-12411","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-12411","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-06-26T16:02:55.284Z","patch_url":"https://github.com/canonical/lxd/pull/18585","primary_source":"","published":"2026-06-26T15:27:55.111Z"},{"affected":"4.12.0 < 5.0.7; 5.1.0 < 5.21.5; 6.0.0 < 6.8.0","affected_versions_present":true,"cve_id":"CVE-2026-34179","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34179","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-09T11:54:18.487Z","patch_url":"https://github.com/canonical/lxd/pull/17936","primary_source":"","published":"2026-04-09T09:22:14.693Z"},{"affected":"4.12.0 < 5.0.7; 5.1.0 < 5.21.5; 6.0.0 < 6.8.0","affected_versions_present":true,"cve_id":"CVE-2026-34178","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34178","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-09T11:55:20.431Z","patch_url":"","primary_source":"","published":"2026-04-09T09:18:58.404Z"},{"affected":"4.12.0 < 5.0.7; 5.1.0 < 5.21.5; 6.0.0 < 6.8.0","affected_versions_present":true,"cve_id":"CVE-2026-34177","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34177","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-09T12:12:48.251Z","patch_url":"","primary_source":"","published":"2026-04-09T09:15:27.532Z"},{"affected":"lxd: 6.0 < 6.7, 5.21.0 < 5.21.4, 5.0.0 < 5.0.6, 4.12","affected_versions_present":true,"cve_id":"CVE-2026-28384","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28384","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-13T16:30:06.396Z","patch_url":"https://github.com/canonical/lxd/commit/043696a13171ace7dd4c2b32d34ce039ab629052","primary_source":"","published":"2026-03-12T14:51:29.991Z"},{"affected":"6.6","affected_versions_present":true,"cve_id":"CVE-2026-3351","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-3351","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-05T17:20:25.645Z","patch_url":"https://github.com/canonical/lxd/pull/17738","primary_source":"","published":"2026-03-03T12:49:25.034Z"},{"affected":"6.0 < 6.5; 5.21 < 5.21.4","affected_versions_present":true,"cve_id":"CVE-2025-54293","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54293","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-02T15:53:20.364Z","patch_url":"","primary_source":"","published":"2025-10-02T10:43:58.246Z"},{"affected":"6.0 < 6.5; 5.21 < 5.21.4","affected_versions_present":true,"cve_id":"CVE-2025-54292","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54292","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-02T15:53:35.597Z","patch_url":"","primary_source":"","published":"2025-10-02T09:26:39.228Z"},{"affected":"6.0 < 6.5; 5.21 < 5.21.4","affected_versions_present":true,"cve_id":"CVE-2025-54291","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54291","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-02T17:29:54.196Z","patch_url":"","primary_source":"","published":"2025-10-02T09:25:42.466Z"},{"affected":"6.0 < 6.5; 5.21 < 5.21.4","affected_versions_present":true,"cve_id":"CVE-2025-54290","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54290","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-02T17:31:02.699Z","patch_url":"","primary_source":"","published":"2025-10-02T09:24:12.894Z"},{"affected":"6 < 6.5; 5.21 < 5.21.4","affected_versions_present":true,"cve_id":"CVE-2025-54289","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54289","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-26T17:48:23.663Z","patch_url":"","primary_source":"","published":"2025-10-02T09:23:03.238Z"},{"affected":"6.0 < 6.5; 5.21 < 5.21.4","affected_versions_present":true,"cve_id":"CVE-2025-54288","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54288","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-02T13:22:55.575Z","patch_url":"","primary_source":"","published":"2025-10-02T09:20:33.135Z"},{"affected":"6.0 < 6.5; 5.21 < 5.21.4","affected_versions_present":true,"cve_id":"CVE-2025-54287","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54287","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-02T13:27:42.957Z","patch_url":"","primary_source":"","published":"2025-10-02T09:16:02.241Z"},{"affected":"5.0 < 5.0.5; 5.21 < 5.21.4; 6.0 < 6.5","affected_versions_present":true,"cve_id":"CVE-2025-54286","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54286","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-26T17:48:23.958Z","patch_url":"","primary_source":"","published":"2025-10-02T09:12:49.044Z"},{"affected":"< 5.21.1","affected_versions_present":true,"cve_id":"CVE-2024-6219","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-6219","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-08-28T13:29:18.834Z","patch_url":"","primary_source":"","published":"2024-12-05T23:13:19.635Z"},{"affected":"4.0 < 4.0.10; 4.0 < 5.0.4; 4.0 < 5.21.2; 4.0 < 6.1","affected_versions_present":true,"cve_id":"CVE-2024-6156","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-6156","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-03-18T15:58:10.503Z","patch_url":"","primary_source":"","published":"2024-12-05T23:11:04.815Z"},{"affected":"version range in vendor record","affected_versions_present":true,"cve_id":"CVE-2023-49721","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-49721","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-10-24T16:44:29.650Z","patch_url":"","primary_source":"","published":"2024-02-14T21:57:40.878Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"Canonical Ltd."}}
