Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/lxc/incus/v6/cmd/incusd
  4. ›
  5. CVE-2026-35527

CVE-2026-35527: Incus has Blind SSRF via Image Import Preflight HEAD

May 4, 2026 (updated May 8, 2026)

A partial implementation of our restricted.images.servers project restriction allows users in such restricted projects to still cause Incus to send HEAD requests to arbitrary endpoints.

The actual image download will be rejected by the project restriction, but the ability to trigger arbitrary HTTP requests inside of the Incus environment can still be used as a way to discover otherwise hidden details about the environment.

References

  • github.com/advisories/GHSA-8gw4-p4wq-4hcv
  • github.com/lxc/incus
  • github.com/lxc/incus/blob/v6.22.0/cmd/incusd/images.go
  • github.com/lxc/incus/security/advisories/GHSA-8gw4-p4wq-4hcv
  • nvd.nist.gov/vuln/detail/CVE-2026-35527

Code Behaviors & Features

Detect and mitigate CVE-2026-35527 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 7.0.0

Fixed versions

  • 7.0.0

Solution

Upgrade to version 7.0.0 or above.

Impact 5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-918: Server-Side Request Forgery (SSRF)

Source file

go/github.com/lxc/incus/v6/cmd/incusd/CVE-2026-35527.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 09 May 2026 12:18:53 +0000.