github.com/lxc/incus/v7
Powerful system container and virtual machine manager
Activity
- Latest release
- 2w ago
- Total releases
- 6
- Cadence
- ~27 days
- Last 12 months
- 6
Reach
- Stars
- 6.1k
Details
- First release
- May 01, 2026
| Version | Released | |
|---|---|---|
v7.4.0
minor
|
v7.4.0
minor
Dependencies (75)
+ 67 more |
|
v7.3.0
minor
|
v7.3.0
minor
Dependencies (73)
+ 65 more |
|
v7.0.1
patch
12 CVEs
CVE-2026-55622
GO-2026-6319
GHSA-c9f5-j9c3-mhrg
Sep 02, 2026
Incus has a project restriction bypass in instance copy across projects in github.com/lxc/incus Incus has a project restriction bypass in instance copy across projects in github.com/lxc/incus Fixed in
7.2.0
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55621
GO-2026-6318
GHSA-64f3-v33m-w89f
Sep 02, 2026
Incus has a project restriction bypass for custom volume copy across projects in github.com/lxc/incus Incus has a project restriction bypass for custom volume copy across projects in github.com/lxc/incus Fixed in
7.2.0
References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-48769
GO-2026-5806
GHSA-f6m5-xw2g-xc4x
Jul 07, 2026
Incus has an arbitrary file write on its client due to trusted image hash in github.com/lxc/incus Incus has an arbitrary file write on its client due to trusted image hash in github.com/lxc/incus Fixed in
7.2.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48754
GO-2026-5800
GHSA-4xg6-52mh-fpw8
Jul 07, 2026
Incus: Nil-pointer dereference in createDependentVolumesFromBackup on disk.{Volume,VolumeSnapshots,Pool} in github.com/lxc/incus Incus: Nil-pointer dereference in createDependentVolumesFromBackup on disk.{Volume,VolumeSnapshots,Pool} in github.com/lxc/incus Fixed in
7.1.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48756
GO-2026-5810
GHSA-xhqx-mgh3-3h7q
Jul 07, 2026
Incus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapshots[*].expires_at (sibling-field variant of GHSA-r7w7) in github.com/lxc/incus Incus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapshots[*].expires_at (sibling-field variant of GHSA-r7w7) in github.com/lxc/incus Fixed in
7.1.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48749
GO-2026-5798
GHSA-2q3f-q5pq-g8wv
Jul 07, 2026
Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image in github.com/lxc/incus Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image in github.com/lxc/incus Fixed in
7.2.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48751
GO-2026-5799
GHSA-48q5-w887-33wv
Jul 07, 2026
Incus has a restricted project bypass leading to arbitrary command execution in github.com/lxc/incus Incus has a restricted project bypass leading to arbitrary command execution in github.com/lxc/incus Fixed in
7.2.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48750
GO-2026-5801
GHSA-73hr-m85f-64v9
Jul 07, 2026
Incus has an arbitrary file write on host via `exec-output` symlink in crafted image in github.com/lxc/incus Incus has an arbitrary file write on host via Fixed in
7.2.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48753
GO-2026-5802
GHSA-ccjc-4qc3-jxqc
Jul 07, 2026
Incus has an arbitrary file write via path traversal in S3 multipart upload in github.com/lxc/incus Incus has an arbitrary file write via path traversal in S3 multipart upload in github.com/lxc/incus Fixed in
7.1.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48752
GO-2026-5803
GHSA-vxp5-584q-c479
Jul 07, 2026
Incus has arbitrary file read+write on host via templates/ symlink in malicious image in github.com/lxc/incus Incus has arbitrary file read+write on host via templates/ symlink in malicious image in github.com/lxc/incus Fixed in
7.2.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48755
GO-2026-5808
GHSA-v6mj-8pf4-hhw4
Jul 07, 2026
Incus has an argument injection in backup compression algorithm leading to AFW and ACE in github.com/lxc/incus Incus has an argument injection in backup compression algorithm leading to AFW and ACE in github.com/lxc/incus Fixed in
7.2.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-47753
GO-2026-5252
GHSA-8g7m-96c8-8wwc
Jun 25, 2026
Incus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted) in github.com/lxc/incus Incus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted) in github.com/lxc/incus Fixed in
7.1.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v7.0.1
patch
Dependencies (73)
+ 65 more |
|
v7.2.0
minor
|
v7.2.0
minor
Dependencies (72)
+ 64 more |
|
v7.1.0
minor
8 CVEs
CVE-2026-55622
GO-2026-6319
GHSA-c9f5-j9c3-mhrg
Sep 02, 2026
Incus has a project restriction bypass in instance copy across projects in github.com/lxc/incus Incus has a project restriction bypass in instance copy across projects in github.com/lxc/incus Fixed in
7.2.0
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55621
GO-2026-6318
GHSA-64f3-v33m-w89f
Sep 02, 2026
Incus has a project restriction bypass for custom volume copy across projects in github.com/lxc/incus Incus has a project restriction bypass for custom volume copy across projects in github.com/lxc/incus Fixed in
7.2.0
References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-48769
GO-2026-5806
GHSA-f6m5-xw2g-xc4x
Jul 07, 2026
Incus has an arbitrary file write on its client due to trusted image hash in github.com/lxc/incus Incus has an arbitrary file write on its client due to trusted image hash in github.com/lxc/incus Fixed in
7.2.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48749
GO-2026-5798
GHSA-2q3f-q5pq-g8wv
Jul 07, 2026
Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image in github.com/lxc/incus Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image in github.com/lxc/incus Fixed in
7.2.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48751
GO-2026-5799
GHSA-48q5-w887-33wv
Jul 07, 2026
Incus has a restricted project bypass leading to arbitrary command execution in github.com/lxc/incus Incus has a restricted project bypass leading to arbitrary command execution in github.com/lxc/incus Fixed in
7.2.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48750
GO-2026-5801
GHSA-73hr-m85f-64v9
Jul 07, 2026
Incus has an arbitrary file write on host via `exec-output` symlink in crafted image in github.com/lxc/incus Incus has an arbitrary file write on host via Fixed in
7.2.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48752
GO-2026-5803
GHSA-vxp5-584q-c479
Jul 07, 2026
Incus has arbitrary file read+write on host via templates/ symlink in malicious image in github.com/lxc/incus Incus has arbitrary file read+write on host via templates/ symlink in malicious image in github.com/lxc/incus Fixed in
7.2.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48755
GO-2026-5808
GHSA-v6mj-8pf4-hhw4
Jul 07, 2026
Incus has an argument injection in backup compression algorithm leading to AFW and ACE in github.com/lxc/incus Incus has an argument injection in backup compression algorithm leading to AFW and ACE in github.com/lxc/incus Fixed in
7.2.0
Updated Jul 07, 2026 · Source: OSV.dev |
v7.1.0
minor
Dependencies (73)
+ 65 more |
|
v7.0.0
initial
12 CVEs
CVE-2026-55622
GO-2026-6319
GHSA-c9f5-j9c3-mhrg
Sep 02, 2026
Incus has a project restriction bypass in instance copy across projects in github.com/lxc/incus Incus has a project restriction bypass in instance copy across projects in github.com/lxc/incus Fixed in
7.2.0
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-55621
GO-2026-6318
GHSA-64f3-v33m-w89f
Sep 02, 2026
Incus has a project restriction bypass for custom volume copy across projects in github.com/lxc/incus Incus has a project restriction bypass for custom volume copy across projects in github.com/lxc/incus Fixed in
7.2.0
References Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-48769
GO-2026-5806
GHSA-f6m5-xw2g-xc4x
Jul 07, 2026
Incus has an arbitrary file write on its client due to trusted image hash in github.com/lxc/incus Incus has an arbitrary file write on its client due to trusted image hash in github.com/lxc/incus Fixed in
7.2.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48754
GO-2026-5800
GHSA-4xg6-52mh-fpw8
Jul 07, 2026
Incus: Nil-pointer dereference in createDependentVolumesFromBackup on disk.{Volume,VolumeSnapshots,Pool} in github.com/lxc/incus Incus: Nil-pointer dereference in createDependentVolumesFromBackup on disk.{Volume,VolumeSnapshots,Pool} in github.com/lxc/incus Fixed in
7.1.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48756
GO-2026-5810
GHSA-xhqx-mgh3-3h7q
Jul 07, 2026
Incus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapshots[*].expires_at (sibling-field variant of GHSA-r7w7) in github.com/lxc/incus Incus: CreateCustomVolumeFromBackup nil-pointer dereference on volume_snapshots[*].expires_at (sibling-field variant of GHSA-r7w7) in github.com/lxc/incus Fixed in
7.1.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48749
GO-2026-5798
GHSA-2q3f-q5pq-g8wv
Jul 07, 2026
Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image in github.com/lxc/incus Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image in github.com/lxc/incus Fixed in
7.2.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48751
GO-2026-5799
GHSA-48q5-w887-33wv
Jul 07, 2026
Incus has a restricted project bypass leading to arbitrary command execution in github.com/lxc/incus Incus has a restricted project bypass leading to arbitrary command execution in github.com/lxc/incus Fixed in
7.2.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48750
GO-2026-5801
GHSA-73hr-m85f-64v9
Jul 07, 2026
Incus has an arbitrary file write on host via `exec-output` symlink in crafted image in github.com/lxc/incus Incus has an arbitrary file write on host via Fixed in
7.2.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48753
GO-2026-5802
GHSA-ccjc-4qc3-jxqc
Jul 07, 2026
Incus has an arbitrary file write via path traversal in S3 multipart upload in github.com/lxc/incus Incus has an arbitrary file write via path traversal in S3 multipart upload in github.com/lxc/incus Fixed in
7.1.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48752
GO-2026-5803
GHSA-vxp5-584q-c479
Jul 07, 2026
Incus has arbitrary file read+write on host via templates/ symlink in malicious image in github.com/lxc/incus Incus has arbitrary file read+write on host via templates/ symlink in malicious image in github.com/lxc/incus Fixed in
7.2.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48755
GO-2026-5808
GHSA-v6mj-8pf4-hhw4
Jul 07, 2026
Incus has an argument injection in backup compression algorithm leading to AFW and ACE in github.com/lxc/incus Incus has an argument injection in backup compression algorithm leading to AFW and ACE in github.com/lxc/incus Fixed in
7.2.0
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-47753
GO-2026-5252
GHSA-8g7m-96c8-8wwc
Jun 25, 2026
Incus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted) in github.com/lxc/incus Incus has a Nil-Pointer Dereference Panic via Instance Backup Import (volume omitted) in github.com/lxc/incus Fixed in
7.1.0
References Updated Jun 25, 2026 · Source: OSV.dev |
v7.0.0
initial
Dependencies (71)
+ 63 more |