Server-side Request Forgery (SSRF) Affecting github.com/lxc/incus/v6/cmd/incusd package, versions >=0.0.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.27% (19th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMLXCINCUSV6CMDINCUSD-16419322
  • published5 May 2026
  • disclosed4 May 2026
  • creditstamparm

Introduced: 4 May 2026

CVE-2026-35527  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

There is no fixed version for github.com/lxc/incus/v6/cmd/incusd.

Overview

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the imgPostURLInfo function. An attacker can cause the server to initiate outbound HTTP HEAD requests to arbitrary endpoints by supplying a crafted URL during the image import preflight stage. This can be used to interact with internal services or cloud metadata endpoints accessible from the host, potentially exposing sensitive information about the environment.

CVSS Base Scores

version 4.0
version 3.1