PT-2026-37149 · Incus+1 · Incus+1

·

CVE-2026-41685

·

Published

2026-05-01

·

Updated

2026-07-30

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Incus versions prior to 7.0.0
Description Authenticated users can cause a denial of service by uploading large amounts of data, which may exhaust the disk space of the Incus server and potentially crash the host system. This occurs because multiple binary import paths accept application/octet-stream requests and stream the HTTP request body directly into temporary files on the host without a request-size limit. The daemon uses direct io.Copy operations to write attacker-controlled streams into host storage before any validation or parsing takes place.
This issue affects the following flows:
  • Instance backup import via the '/1.0/instances' endpoint
  • Storage bucket import
  • Storage volume import (including ISO uploads)
The impact is reduced for users utilizing storage.images volume and storage.backups volume, as uploads are stored on those specific volumes rather than the host filesystem, which is the default configuration in IncusOS.
Recommendations Update to version 7.0.0.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09652
CVE-2026-41685
GHSA-98VH-X9CX-9CFP
GO-2026-5280
OPENSUSE-SU-2026:21483-1

Affected Products

Incus
Red Os