VYPR
Moderate severityNVD Advisory· Published Oct 2, 2025· Updated Oct 2, 2025

Project existence disclosure in LXD images API

CVE-2025-54291

Description

Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code responses.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/canonical/lxdGo
>= 4.0, < 5.21.45.21.4
github.com/canonical/lxdGo
>= 6.0, < 6.56.5
github.com/canonical/lxdGo
>= 0.0.0-20200331193331-03aab09f5b5c, < 0.0.0-20250827065555-0494f5d47e410.0.0-20250827065555-0494f5d47e41

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.