PT-2025-40334 · Canonical+2 · Lxd+2

Published

2025-10-02

·

Updated

2025-11-17

·

CVE-2025-54291

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Canonical LXD versions prior to 6.5 Canonical LXD versions prior to 5.21.4
Description An information disclosure issue exists in the images API of Canonical LXD. This allows unauthenticated remote attackers to determine project existence by observing differing HTTP status code responses.
Recommendations Update to a version prior to 6.5. Update to a version prior to 5.21.4.

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-54291
DSA-6027-1
GHSA-XCH9-H8QW-85C7
GO-2025-4005
OPENSUSE-SU-2025:15710-1

Affected Products

Debian
Lxd
Red Os