CVE-2025-54291: Canonical Lxd

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Information disclosure in images API in Canonical LXD before 6.5 and 5.21.4 on all platforms allows unauthenticated remote attackers to determine project existence via differing HTTP status code responses.

Affected products

  • Canonical Lxd: from 4.0.0, before 5.21.4 (fixed in 5.21.4); from 6.1, before 6.5 (fixed in 6.5)

Published 2025-10-02. Last modified 2026-06-17.