{"id":"GO-2026-5576","summary":"LXD: Importing a crafted backup leads to project restriction bypass in github.com/canonical/lxd","details":"LXD: Importing a crafted backup leads to project restriction bypass in github.com/canonical/lxd","aliases":["CVE-2026-34178","GHSA-q96j-3fmm-7fv4"],"modified":"2026-08-11T23:45:11.013325155Z","published":"2026-08-11T23:21:27Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-5576"},"references":[{"type":"ADVISORY","url":"https://github.com/canonical/lxd/security/advisories/GHSA-q96j-3fmm-7fv4"},{"type":"FIX","url":"https://github.com/canonical/lxd/pull/17921"}],"affected":[{"package":{"name":"github.com/canonical/lxd","ecosystem":"Go","purl":"pkg:golang/github.com/canonical/lxd"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-20210305023314-538ac3df036e"}]}],"ecosystem_specific":{"imports":[{"symbols":["GetInfo"],"path":"github.com/canonical/lxd/lxd/backup"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5576.json"}}],"schema_version":"1.9.0"}