{"id":"CVE-2026-3351","details":"Improper authorization in the API endpoint GET /1.0/certificates in Canonical LXD 6.6 on Linux allows an authenticated, restricted user to enumerate all certificate fingerprints trusted by the lxd server.","aliases":["GHSA-crmg-9m86-636r","GO-2026-4595"],"modified":"2026-04-10T05:42:49.520471Z","published":"2026-03-03T13:16:21.350Z","related":["SUSE-SU-2026:1042-1"],"references":[{"type":"FIX","url":"https://github.com/canonical/lxd/commit/d936c90d47cf0be1e9757df897f769e9887ebde1"},{"type":"FIX","url":"https://github.com/canonical/lxd/pull/17738"},{"type":"EVIDENCE","url":"https://github.com/canonical/lxd/security/advisories/GHSA-crmg-9m86-636r"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/canonical/lxd","events":[{"introduced":"0"},{"last_affected":"49569b65625b9c53dc5dce885ca2cb1390fd6481"},{"fixed":"d936c90d47cf0be1e9757df897f769e9887ebde1"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"6.6"}]}}],"versions":["lxd-0.1","lxd-0.10","lxd-0.11","lxd-0.12","lxd-0.13","lxd-0.14","lxd-0.15","lxd-0.16","lxd-0.17","lxd-0.18","lxd-0.19","lxd-0.2","lxd-0.20","lxd-0.21","lxd-0.22","lxd-0.23","lxd-0.24","lxd-0.25","lxd-0.26","lxd-0.27","lxd-0.3","lxd-0.4","lxd-0.5","lxd-0.6","lxd-0.7","lxd-0.8","lxd-0.8.1","lxd-0.9","lxd-2.0.0","lxd-2.0.0.beta1","lxd-2.0.0.beta2","lxd-2.0.0.beta3","lxd-2.0.0.beta4","lxd-2.0.0.rc1","lxd-2.0.0.rc2","lxd-2.0.0.rc3","lxd-2.0.0.rc4","lxd-2.0.0.rc5","lxd-2.0.0.rc6","lxd-2.0.0.rc7","lxd-2.0.0.rc8","lxd-2.0.0.rc9","lxd-2.1","lxd-2.10","lxd-2.10.1","lxd-2.11","lxd-2.12","lxd-2.13","lxd-2.14","lxd-2.15","lxd-2.16","lxd-2.17","lxd-2.18","lxd-2.19","lxd-2.2","lxd-2.20","lxd-2.21","lxd-2.3","lxd-2.4","lxd-2.4.1","lxd-2.5","lxd-2.6","lxd-2.6.1","lxd-2.6.2","lxd-2.7","lxd-2.8","lxd-2.9","lxd-2.9.1","lxd-2.9.2","lxd-2.9.3","lxd-3.0.0","lxd-3.0.0.beta1","lxd-3.0.0.beta2","lxd-3.0.0.beta3","lxd-3.0.0.beta4","lxd-3.0.0.beta5","lxd-3.0.0.beta6","lxd-3.0.0.beta7","lxd-3.1","lxd-3.10","lxd-3.11","lxd-3.12","lxd-3.13","lxd-3.14","lxd-3.15","lxd-3.16","lxd-3.17","lxd-3.18","lxd-3.19","lxd-3.2","lxd-3.20","lxd-3.21","lxd-3.22","lxd-3.23","lxd-3.3","lxd-3.4","lxd-3.5","lxd-3.6","lxd-3.7","lxd-3.8","lxd-3.9","lxd-4.0.0","lxd-4.1","lxd-4.10","lxd-4.11","lxd-4.12","lxd-4.13","lxd-4.14","lxd-4.15","lxd-4.16","lxd-4.17","lxd-4.18","lxd-4.19","lxd-4.2","lxd-4.20","lxd-4.21","lxd-4.22","lxd-4.23","lxd-4.24","lxd-4.3","lxd-4.4","lxd-4.5","lxd-4.6","lxd-4.7","lxd-4.8","lxd-4.9","lxd-5.0.0","lxd-5.1","lxd-5.10","lxd-5.11","lxd-5.12","lxd-5.13","lxd-5.14","lxd-5.15","lxd-5.16","lxd-5.17","lxd-5.2","lxd-5.3","lxd-5.4","lxd-5.5","lxd-5.6","lxd-5.7","lxd-5.8","lxd-5.9","lxd-6.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-3351.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}