CVE Explorer
CVE-2026-35527
Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an outbound HEAD request to a user-supplied URL before validating the request against project restrictions such as restricted.images.servers. The imgPostURLInfo function constructs and sends a HEAD request directly from the attacker-supplied source URL to resolve image metadata, and this network interaction occurs before the flow reaches the point where the import would be reje
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"incus","vendor":"lxc","versions":[{"status":"affected","version":"< 7.0.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c57571358e2a3a2766c94cacb13466e93f7f373c1d4a418dc078d2672d281b88 · sha256:07c644fe7a3daf19… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":5.3,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:c57571358e2a3a2766c94cacb13466e93f7f373c1d4a418dc078d2672d281b88 · sha256:07c644fe7a3daf19… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c57571358e2a3a2766c94cacb13466e93f7f373c1d4a418dc078d2672d281b88 · sha256:07c644fe7a3daf19… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/lxc/incus/blob/v6.22.0/cmd/incusd/images.go","tags":["x_refsource_MISC"],"url":"https://github.com/lxc/incus/blob/v6.22.0/cmd/incusd/images.go"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c57571358e2a3a2766c94cacb13466e93f7f373c1d4a418dc078d2672d281b88 · sha256:07c644fe7a3daf19… · /containers/cna/references/1
{"tags":["exploit"],"url":"https://github.com/lxc/incus/security/advisories/GHSA-8gw4-p4wq-4hcv"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c57571358e2a3a2766c94cacb13466e93f7f373c1d4a418dc078d2672d281b88 · sha256:07c644fe7a3daf19… · /containers/adp/0/references/0
{"name":"https://github.com/lxc/incus/security/advisories/GHSA-8gw4-p4wq-4hcv","tags":["x_refsource_CONFIRM"],"url":"https://github.com/lxc/incus/security/advisories/GHSA-8gw4-p4wq-4hcv"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c57571358e2a3a2766c94cacb13466e93f7f373c1d4a418dc078d2672d281b88 · sha256:07c644fe7a3daf19… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.