Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6027-1 | incus security update |
Debian DSA |
DSA-6028-1 | lxd security update |
EUVD |
EUVD-2025-32099 | Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions exploiting client certificate authentication. |
Github GHSA |
GHSA-p8hw-rfjg-689h | Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI |
Thu, 26 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
ssvc
|
Wed, 22 Oct 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux linux Kernel
|
|
| CPEs | cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linux linux Kernel
|
|
| Metrics |
cvssV3_1
|
Fri, 03 Oct 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical lxd Linux Linux linux |
|
| Vendors & Products |
Canonical
Canonical lxd Linux Linux linux |
Thu, 02 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 02 Oct 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions exploiting client certificate authentication. | |
| Title | CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2026-02-26T17:48:23.958Z
Reserved: 2025-07-18T07:59:07.916Z
Link: CVE-2025-54286
Updated: 2025-10-02T13:28:06.576Z
Status : Analyzed
Published: 2025-10-02T10:15:38.427
Modified: 2025-10-22T15:47:31.957
Link: CVE-2025-54286
No data.
OpenCVE Enrichment
Updated: 2025-10-03T08:22:59Z
Debian DSA
EUVD
Github GHSA