<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:43:17 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-254022</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-254022</link>
      <description>EUVD-2026-254022</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-254022</guid>
    </item>
    <item>
      <title>fkie_cve-2025-54291</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-54291</link>
      <description>&lt;p&gt;Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code responses.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code responses.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-54291</guid>
    </item>
    <item>
      <title>GHSA-xch9-h8qw-85c7 — Canonical LXD Project Existence Determination Through Error Handling in Image Get Function</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xch9-h8qw-85c7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/canonical/lxd&lt;/p&gt;
&lt;p&gt;### Impact
The LXD /1.0/images endpoint is implemented as an AllowUntrusted API that requires no authentication, making it accessible to users without accounts. This API allows determining project existence through differences in HTTP status codes when accessed with the project parameter.&lt;/p&gt;
&lt;p&gt;https://github.com/canonical/lxd/blob/43d5189564d27f6161b430ed258c8b56603c2759/lxd/images.go#L63-L69&lt;/p&gt;
&lt;p&gt;This configuration allows access without authentication:&lt;/p&gt;
&lt;p&gt;https://github.com/canonical/lxd/blob/43d5189564d27f6161b430ed258c8b56603c2759/lxd/daemon.go#L924-L926&lt;/p&gt;
&lt;p&gt;This API returns a 404 error when accessing existing projects and a 403 error when accessing non-existent projects, allowing confirmation of project existence through this difference.&lt;/p&gt;
&lt;p&gt;The problematic implementation is shown below.&lt;/p&gt;
&lt;p&gt;First, in the error handling implementation of the imagesGet function below, project existence is checked within the `projectutils.ImageProject` function, and the err returned by the `ImageProject` function is directly returned to the user.&lt;/p&gt;
&lt;p&gt;https://github.com/canonical/lxd/blob/43d5189564d27f6161b430ed258c8b56603c2759/lxd/i mages.go#L1781-L1788&lt;/p&gt;
&lt;p&gt;When the project doesn&amp;#39;t exist, the error is 404 (http.StatusNotFound), which is
returned to the user:&lt;/p&gt;
&lt;p&gt;https://github.com/canonical/lxd/blob/43d5189564d27f6161b430ed258c8b56603c2759/lxd/db/cluster/projects.mapper.go#L237-L239&lt;/p&gt;
&lt;p&gt;On the other hand, when the project exists but the user lacks viewing permissions, the imagesGet function returns 403 (response.Forb…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/canonical/lxd&lt;/p&gt;
&lt;p&gt;### Impact
The LXD /1.0/images endpoint is implemented as an AllowUntrusted API that requires no authentication, making it accessible to users without accounts. This API allows determining project existence through differences in HTTP status codes when accessed with the project parameter.&lt;/p&gt;
&lt;p&gt;https://github.com/canonical/lxd/blob/43d5189564d27f6161b430ed258c8b56603c2759/lxd/images.go#L63-L69&lt;/p&gt;
&lt;p&gt;This configuration allows access without authentication:&lt;/p&gt;
&lt;p&gt;https://github.com/canonical/lxd/blob/43d5189564d27f6161b430ed258c8b56603c2759/lxd/daemon.go#L924-L926&lt;/p&gt;
&lt;p&gt;This API returns a 404 error when accessing existing projects and a 403 error when accessing non-existent projects, allowing confirmation of project existence through this difference.&lt;/p&gt;
&lt;p&gt;The problematic implementation is shown below.&lt;/p&gt;
&lt;p&gt;First, in the error handling implementation of the imagesGet function below, project existence is checked within the `projectutils.ImageProject` function, and the err returned by the `ImageProject` function is directly returned to the user.&lt;/p&gt;
&lt;p&gt;https://github.com/canonical/lxd/blob/43d5189564d27f6161b430ed258c8b56603c2759/lxd/i mages.go#L1781-L1788&lt;/p&gt;
&lt;p&gt;When the project doesn&amp;#39;t exist, the error is 404 (http.StatusNotFound), which is
returned to the user:&lt;/p&gt;
&lt;p&gt;https://github.com/canonical/lxd/blob/43d5189564d27f6161b430ed258c8b56603c2759/lxd/db/cluster/projects.mapper.go#L237-L239&lt;/p&gt;
&lt;p&gt;On the other hand, when the project exists but the user lacks viewing permissions, the imagesGet function returns 403 (response.Forb…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xch9-h8qw-85c7</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15710-1 — govulncheck-vulndb-0.0.20251105T184115-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15710-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20251105T184115-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20251105T184115-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15710-1</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2025-54291</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-54291</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: lxd, Ubuntu:Pro:18.04:LTS: lxd, Ubuntu:20.04:LTS: lxd&lt;/p&gt;
&lt;p&gt;Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code responses.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: lxd, Ubuntu:Pro:18.04:LTS: lxd, Ubuntu:20.04:LTS: lxd&lt;/p&gt;
&lt;p&gt;Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code responses.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-54291</guid>
    </item>
  </channel>
</rss>
