CVE Explorer
CVE-2026-33743
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API. This does not impact any running workload, existing containers and virtual machines will keep operating. Version 6.23.0 fixes the issue.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"incus","vendor":"lxc","versions":[{"status":"affected","version":"< 6.23.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e56e7530d345f1453eeb850552b1d3fa31690aabc600663023aa9ce24e949f50 · sha256:0e47a0c4fa24c393… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:e56e7530d345f1453eeb850552b1d3fa31690aabc600663023aa9ce24e949f50 · sha256:0e47a0c4fa24c393… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-770","description":"CWE-770: Allocation of Resources Without Limits or Throttling","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e56e7530d345f1453eeb850552b1d3fa31690aabc600663023aa9ce24e949f50 · sha256:0e47a0c4fa24c393… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["exploit"],"url":"https://github.com/lxc/incus/security/advisories/GHSA-vg76-xmhg-j5x3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e56e7530d345f1453eeb850552b1d3fa31690aabc600663023aa9ce24e949f50 · sha256:0e47a0c4fa24c393… · /containers/adp/0/references/0
{"name":"https://github.com/lxc/incus/security/advisories/GHSA-vg76-xmhg-j5x3","tags":["x_refsource_CONFIRM"],"url":"https://github.com/lxc/incus/security/advisories/GHSA-vg76-xmhg-j5x3"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e56e7530d345f1453eeb850552b1d3fa31690aabc600663023aa9ce24e949f50 · sha256:0e47a0c4fa24c393… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.