Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/canonical/lxd(Go) | 4.0 | 5.21.4 | N/A |
| github.com/canonical/lxd(Go) | 6.0 | 6.5 | N/A |
| github.com/canonical/lxd(Go) | 0.0.0-20200331193331-03aab09f5b5c | 0.0.0-20250827065555-0494f5d47e41 | N/A |
CVSS Metrics