<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 15:36:28 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-254023</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-254023</link>
      <description>EUVD-2026-254023</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-254023</guid>
    </item>
    <item>
      <title>fkie_cve-2025-54290</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-54290</link>
      <description>&lt;p&gt;Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-54290</guid>
    </item>
    <item>
      <title>GHSA-p3x5-mvmp-5f35 — Canonical LXD Project Existence Determination Through Error Handling in Image Export Function</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-p3x5-mvmp-5f35</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/canonical/lxd&lt;/p&gt;
&lt;p&gt;### Impact
In LXD&amp;#39;s images export API (`/1.0/images/{fingerprint}/export`), implementation differences in error handling allow determining project existence without authentication.&lt;/p&gt;
&lt;p&gt;Specifically, in the following code, errors when multiple images match are directly returned to users as API responses:&lt;/p&gt;
&lt;p&gt;https://github.com/canonical/lxd/blob/43d5189564d27f6161b430ed258c8b56603c2759/lxd/db/images.go#L239-L246&lt;/p&gt;
&lt;p&gt;While fingerprints generally don&amp;#39;t duplicate, this functionality uses fingerprints with LIKE clauses, allowing prefix specification. Therefore, using LIKE wildcards such as % will match multiple images if multiple images exist in the project.&lt;/p&gt;
&lt;p&gt;https://github.com/canonical/lxd/blob/43d5189564d27f6161b430ed258c8b56603c2759/lxd/db/images.go#L277-L286&lt;/p&gt;
&lt;p&gt;In the above implementation, multiple matches result in a 500 error, but if the project itself doesn&amp;#39;t exist, there are 0 matches and a 404 is returned.&lt;/p&gt;
&lt;p&gt;1. When project exists and multiple images match: HTTP 500 error &amp;#34;More than one image matches&amp;#34;
2. When project doesn&amp;#39;t exist: HTTP 404 error &amp;#34;not found&amp;#34; 
 
This behavioural difference allows attackers to confirm project existence without authentication.&lt;/p&gt;
&lt;p&gt;### Reproduction Steps
1. Send a request with a pattern matching multiple entries to an existing project (default):&lt;/p&gt;
&lt;p&gt;```
curl -k &amp;#39;https://lxd-host:8443/1.0/images/%25/export?project=default&amp;amp;secret=x&amp;#39;
```&lt;/p&gt;
&lt;p&gt;Response:&lt;/p&gt;
&lt;p&gt;```json
{&amp;#34;type&amp;#34;:&amp;#34;error&amp;#34;,&amp;#34;status&amp;#34;:&amp;#34;&amp;#34;,&amp;#34;status_code&amp;#34;:0,&amp;#34;operation&amp;#34;:&amp;#34;&amp;#34;,&amp;#34;error_code&amp;#34;:500,&amp;#34;error&amp;#34;:&amp;#34;More than one image…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/canonical/lxd&lt;/p&gt;
&lt;p&gt;### Impact
In LXD&amp;#39;s images export API (`/1.0/images/{fingerprint}/export`), implementation differences in error handling allow determining project existence without authentication.&lt;/p&gt;
&lt;p&gt;Specifically, in the following code, errors when multiple images match are directly returned to users as API responses:&lt;/p&gt;
&lt;p&gt;https://github.com/canonical/lxd/blob/43d5189564d27f6161b430ed258c8b56603c2759/lxd/db/images.go#L239-L246&lt;/p&gt;
&lt;p&gt;While fingerprints generally don&amp;#39;t duplicate, this functionality uses fingerprints with LIKE clauses, allowing prefix specification. Therefore, using LIKE wildcards such as % will match multiple images if multiple images exist in the project.&lt;/p&gt;
&lt;p&gt;https://github.com/canonical/lxd/blob/43d5189564d27f6161b430ed258c8b56603c2759/lxd/db/images.go#L277-L286&lt;/p&gt;
&lt;p&gt;In the above implementation, multiple matches result in a 500 error, but if the project itself doesn&amp;#39;t exist, there are 0 matches and a 404 is returned.&lt;/p&gt;
&lt;p&gt;1. When project exists and multiple images match: HTTP 500 error &amp;#34;More than one image matches&amp;#34;
2. When project doesn&amp;#39;t exist: HTTP 404 error &amp;#34;not found&amp;#34; 
 
This behavioural difference allows attackers to confirm project existence without authentication.&lt;/p&gt;
&lt;p&gt;### Reproduction Steps
1. Send a request with a pattern matching multiple entries to an existing project (default):&lt;/p&gt;
&lt;p&gt;```
curl -k &amp;#39;https://lxd-host:8443/1.0/images/%25/export?project=default&amp;amp;secret=x&amp;#39;
```&lt;/p&gt;
&lt;p&gt;Response:&lt;/p&gt;
&lt;p&gt;```json
{&amp;#34;type&amp;#34;:&amp;#34;error&amp;#34;,&amp;#34;status&amp;#34;:&amp;#34;&amp;#34;,&amp;#34;status_code&amp;#34;:0,&amp;#34;operation&amp;#34;:&amp;#34;&amp;#34;,&amp;#34;error_code&amp;#34;:500,&amp;#34;error&amp;#34;:&amp;#34;More than one image…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-p3x5-mvmp-5f35</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15710-1 — govulncheck-vulndb-0.0.20251105T184115-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15710-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20251105T184115-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20251105T184115-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15710-1</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2025-54290</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-54290</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: lxd, Ubuntu:Pro:18.04:LTS: lxd, Ubuntu:20.04:LTS: lxd&lt;/p&gt;
&lt;p&gt;Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: lxd, Ubuntu:Pro:18.04:LTS: lxd, Ubuntu:20.04:LTS: lxd&lt;/p&gt;
&lt;p&gt;Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-54290</guid>
    </item>
  </channel>
</rss>
