Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6027-1 | incus security update |
EUVD |
EUVD-2025-32095 | Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints. |
Github GHSA |
GHSA-p3x5-mvmp-5f35 | Canonical LXD Project Existence Determination Through Error Handling in Image Export Function |
Fri, 24 Oct 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux linux Kernel
|
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:canonical:lxd:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Linux linux Kernel
|
|
| Metrics |
cvssV3_1
|
Fri, 03 Oct 2025 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Canonical
Canonical lxd Linux Linux linux |
|
| Vendors & Products |
Canonical
Canonical lxd Linux Linux linux |
Thu, 02 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 02 Oct 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints. | |
| Title | Project Existence Disclosure via Error Handling in LXD Image Export | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: canonical
Published:
Updated: 2025-10-02T17:31:02.699Z
Reserved: 2025-07-18T07:59:07.917Z
Link: CVE-2025-54290
Updated: 2025-10-02T17:30:57.839Z
Status : Analyzed
Published: 2025-10-02T10:15:39.227
Modified: 2025-10-24T14:20:05.930
Link: CVE-2025-54290
No data.
OpenCVE Enrichment
Updated: 2025-10-03T08:22:50Z
Debian DSA
EUVD
Github GHSA