CVE-2026-33743
Incus vulnerable to denial of source through crafted bucket backup file in github.com/lxc/incus
6.5
MEDIUM
CVSS 3.1
EPSS 0.02%
Description
Incus is a system container and virtual machine manager. Prior to version 6.23.0, a specially crafted storage bucket backup can be used by an user with access to Incus' storage bucket feature to crash the Incus daemon. Repeated use of this attack can be used to keep the server offline causing a denial of service of the control plane API. This does not impact any running workload, existing containers and virtual machines will keep operating. Version 6.23.0 fixes the issue.
How to fix CVE-2026-33743
To remediate CVE-2026-33743, upgrade the affected package to a fixed version below.
- —upgrade to 6.0.4-2+deb13u5 or later
- —no fix listed
- —no fix listed
- —upgrade to 6.23.0 or later
- —upgrade to 6.23.0 or later
Is CVE-2026-33743 being exploited?
Low — EPSS is 0.0%, meaning exploitation activity has not been observed at scale.
Affected packages (5)
- from 0, < 6.0.4-2+deb13u5
- from 0, <= 0.7.0
- from 0
- from 0, < 6.23.0
- from 0, < 6.23.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |