{"api_version":"v1","generated_at":"2026-10-08T19:20:00+00:00","product":{"cve_count":38,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-lxc-incus-6d3bd6c36a7c","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/incus","name":"incus","next_cursor":null,"observations":[{"affected":"incus: < 7.3.0","affected_versions_present":true,"cve_id":"CVE-2026-63343","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63343","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-21T21:44:03.623Z","patch_url":"","primary_source":"","published":"2026-08-21T14:53:26.109Z"},{"affected":"incus: < 7.3.0","affected_versions_present":true,"cve_id":"CVE-2026-63125","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-63125","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-21T15:02:55.718Z","patch_url":"","primary_source":"","published":"2026-08-21T14:49:16.844Z"},{"affected":"incus: < 7.3.0","affected_versions_present":true,"cve_id":"CVE-2026-62941","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62941","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-21T16:44:16.507Z","patch_url":"","primary_source":"","published":"2026-08-21T14:47:56.724Z"},{"affected":"incus: < 7.3.0","affected_versions_present":true,"cve_id":"CVE-2026-62940","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62940","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-21T15:13:46.664Z","patch_url":"","primary_source":"","published":"2026-08-21T14:47:13.386Z"},{"affected":"incus: < 7.3.0","affected_versions_present":true,"cve_id":"CVE-2026-62867","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62867","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-21T21:44:10.367Z","patch_url":"","primary_source":"","published":"2026-08-21T14:45:35.859Z"},{"affected":"incus: < 7.3.0","affected_versions_present":true,"cve_id":"CVE-2026-62313","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-62313","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-26T17:27:33.674Z","patch_url":"","primary_source":"","published":"2026-08-21T14:44:27.324Z"},{"affected":"incus: < 7.2.0","affected_versions_present":true,"cve_id":"CVE-2026-55622","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55622","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-21T15:35:57.698Z","patch_url":"","primary_source":"","published":"2026-08-21T14:40:35.432Z"},{"affected":"incus: < 7.2.0","affected_versions_present":true,"cve_id":"CVE-2026-55621","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55621","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-21T16:41:23.236Z","patch_url":"","primary_source":"","published":"2026-08-21T14:39:43.775Z"},{"affected":"incus: < 7.2.0","affected_versions_present":true,"cve_id":"CVE-2026-48769","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48769","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-21T15:16:24.468Z","patch_url":"","primary_source":"","published":"2026-08-21T14:38:38.984Z"},{"affected":"incus: < 7.2.0","affected_versions_present":true,"cve_id":"CVE-2026-48755","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48755","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-21T21:44:16.989Z","patch_url":"","primary_source":"","published":"2026-08-21T14:37:25.389Z"},{"affected":"incus: < 7.1.0","affected_versions_present":true,"cve_id":"CVE-2026-48754","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48754","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-26T17:26:19.767Z","patch_url":"","primary_source":"","published":"2026-08-21T14:36:16.011Z"},{"affected":"incus: < 7.1.0","affected_versions_present":true,"cve_id":"CVE-2026-48753","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48753","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-21T15:36:43.317Z","patch_url":"","primary_source":"","published":"2026-08-21T14:34:39.574Z"},{"affected":"incus: < 7.2.0","affected_versions_present":true,"cve_id":"CVE-2026-48752","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48752","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-21T16:40:20.053Z","patch_url":"","primary_source":"","published":"2026-08-21T14:31:57.555Z"},{"affected":"incus: < 7.2.0","affected_versions_present":true,"cve_id":"CVE-2026-48751","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48751","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-21T15:15:09.821Z","patch_url":"","primary_source":"","published":"2026-08-21T14:21:03.073Z"},{"affected":"incus: < 7.2.0","affected_versions_present":true,"cve_id":"CVE-2026-48750","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48750","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-26T17:24:53.540Z","patch_url":"","primary_source":"","published":"2026-08-21T14:19:45.109Z"},{"affected":"incus: < 7.2.0","affected_versions_present":true,"cve_id":"CVE-2026-48749","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48749","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-21T15:37:47.104Z","patch_url":"","primary_source":"","published":"2026-08-21T14:17:54.009Z"},{"affected":"incus: < 7.1.0","affected_versions_present":true,"cve_id":"CVE-2026-47753","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-47753","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-21T14:39:55.034Z","patch_url":"","primary_source":"","published":"2026-08-21T14:14:12.280Z"},{"affected":"incus: < 7.1.0","affected_versions_present":true,"cve_id":"CVE-2026-48756","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-48756","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-21T21:44:23.844Z","patch_url":"","primary_source":"","published":"2026-08-21T14:10:34.151Z"},{"affected":"< 7.0.0","affected_versions_present":true,"cve_id":"CVE-2026-41685","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41685","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-05-07T13:50:17.247Z","patch_url":"https://github.com/lxc/incus/releases/tag/v7.0.0","primary_source":"","published":"2026-05-07T13:09:34.982Z"},{"affected":"< 7.0.0","affected_versions_present":true,"cve_id":"CVE-2026-41684","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41684","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-05-07T13:45:56.918Z","patch_url":"https://github.com/lxc/incus/releases/tag/v7.0.0","primary_source":"","published":"2026-05-07T13:08:12.792Z"},{"affected":"< 7.0.0","affected_versions_present":true,"cve_id":"CVE-2026-41648","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41648","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-05-07T15:11:42.272Z","patch_url":"https://github.com/lxc/incus/releases/tag/v7.0.0","primary_source":"","published":"2026-05-07T13:05:42.479Z"},{"affected":"< 7.0.0","affected_versions_present":true,"cve_id":"CVE-2026-41647","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41647","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-05-07T13:54:39.907Z","patch_url":"https://github.com/lxc/incus/releases/tag/v7.0.0","primary_source":"","published":"2026-05-07T13:02:15.734Z"},{"affected":"< 7.0.0","affected_versions_present":true,"cve_id":"CVE-2026-40251","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40251","fixed":"7.0.0.","last_modified":"2026-05-07T13:52:33.513Z","patch_url":"https://github.com/lxc/incus/security/advisories/GHSA-4m88-wxj4-9qj6","primary_source":"","published":"2026-05-06T20:40:10.930Z"},{"affected":"< 7.0.0","affected_versions_present":true,"cve_id":"CVE-2026-40243","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40243","fixed":"7.0.0.","last_modified":"2026-05-07T14:03:42.997Z","patch_url":"https://github.com/lxc/incus/security/advisories/GHSA-c839-4qxr-j4x3","primary_source":"","published":"2026-05-06T20:38:22.590Z"},{"affected":"< 7.0.0","affected_versions_present":true,"cve_id":"CVE-2026-40197","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40197","fixed":"7.0.0.","last_modified":"2026-05-07T13:28:55.006Z","patch_url":"https://github.com/lxc/incus/security/advisories/GHSA-r7w7-mmxr-47r9","primary_source":"","published":"2026-05-06T20:36:24.000Z"},{"affected":"< 7.0.0","affected_versions_present":true,"cve_id":"CVE-2026-40195","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40195","fixed":"7.0.0.","last_modified":"2026-05-07T14:01:55.903Z","patch_url":"https://github.com/lxc/incus/security/advisories/GHSA-gc7j-g665-rxr9","primary_source":"","published":"2026-05-06T20:33:34.084Z"},{"affected":"< 7.0.0","affected_versions_present":true,"cve_id":"CVE-2026-35527","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-35527","fixed":"7.0.0.","last_modified":"2026-05-06T15:24:57.848Z","patch_url":"https://github.com/lxc/incus/security/advisories/GHSA-8gw4-p4wq-4hcv","primary_source":"","published":"2026-05-05T19:56:43.388Z"},{"affected":"< 6.23.0","affected_versions_present":true,"cve_id":"CVE-2026-33945","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33945","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-27T20:00:08.359Z","patch_url":"","primary_source":"","published":"2026-03-26T23:27:45.711Z"},{"affected":"< 6.23.0","affected_versions_present":true,"cve_id":"CVE-2026-33898","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33898","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-30T11:48:28.483Z","patch_url":"","primary_source":"","published":"2026-03-26T23:25:45.249Z"},{"affected":"< 6.23.0","affected_versions_present":true,"cve_id":"CVE-2026-33897","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33897","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-27T20:02:55.502Z","patch_url":"","primary_source":"","published":"2026-03-26T22:43:31.392Z"},{"affected":"< 6.23.0","affected_versions_present":true,"cve_id":"CVE-2026-33743","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33743","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-27T13:53:39.299Z","patch_url":"","primary_source":"","published":"2026-03-26T22:40:07.499Z"},{"affected":"< 6.23.0","affected_versions_present":true,"cve_id":"CVE-2026-33711","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33711","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-27T20:00:18.358Z","patch_url":"","primary_source":"","published":"2026-03-26T22:37:29.746Z"},{"affected":"< 6.23.0","affected_versions_present":true,"cve_id":"CVE-2026-33542","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33542","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-30T11:47:37.934Z","patch_url":"https://github.com/lxc/incus/security/advisories/GHSA-p8mm-23gg-jc9r","primary_source":"","published":"2026-03-26T22:32:13.733Z"},{"affected":">= 6.1.0, <= 6.20.0; <= 6.0.5","affected_versions_present":true,"cve_id":"CVE-2026-23954","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23954","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-01-26T21:02:48.738Z","patch_url":"https://github.com/user-attachments/files/24473601/templates_arbitrary_write.patch","primary_source":"","published":"2026-01-22T21:45:55.696Z"},{"affected":">= 6.1.0, <= 6.20.0; <= 6.0.5","affected_versions_present":true,"cve_id":"CVE-2026-23953","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23953","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-01-26T21:00:46.311Z","patch_url":"https://github.com/user-attachments/files/24473685/environment_newline_injection.patch","primary_source":"","published":"2026-01-22T21:39:41.015Z"},{"affected":"< 6.0.6; >= 6.1.0, < 6.19.0","affected_versions_present":true,"cve_id":"CVE-2025-64507","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-64507","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-11-12T20:13:48.233Z","patch_url":"https://github.com/lxc/incus/security/advisories/GHSA-56mx-8g9f-5crf","primary_source":"","published":"2025-11-10T21:56:26.578Z"},{"affected":">= 6.12, <= 6.13","affected_versions_present":true,"cve_id":"CVE-2025-52890","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-52890","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-06-25T17:54:01.093Z","patch_url":"","primary_source":"","published":"2025-06-25T16:51:24.279Z"},{"affected":">= 6.12, <= 6.13","affected_versions_present":true,"cve_id":"CVE-2025-52889","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-52889","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-06-25T17:54:29.213Z","patch_url":"","primary_source":"","published":"2025-06-25T16:49:00.442Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"lxc"}}
