{"id":"CVE-2025-54290","aliases":["GHSA-p3x5-mvmp-5f35","GO-2025-4002"],"url":"https://o3.security/vulnerability/CVE-2025-54290","summary":"Project Existence Disclosure via Error Handling in LXD Image Export","details":"Information disclosure in image export API in Canonical LXD before 6.5 and 5.21.4 on Linux allows network attackers to determine project existence without authentication via crafted requests using wildcard fingerprints.","published":"2025-10-02T09:24:12.894Z","modified":"2026-08-12T03:51:38.090773822Z","cvss":null,"epss":{"score":0.00317,"percentile":0.23836,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/canonical/lxd","fixedVersion":"5.21.4"},{"ecosystem":"Go","name":"github.com/canonical/lxd","fixedVersion":"6.5"},{"ecosystem":"Go","name":"github.com/canonical/lxd","fixedVersion":"0.0.0-20250827065555-0494f5d47e41"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54290.json"},{"type":"ADVISORY","url":"https://github.com/canonical/lxd/security/advisories/GHSA-p3x5-mvmp-5f35"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54290"},{"type":"PACKAGE","url":"https://github.com/canonical/lxd"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:38.090773822Z"}}