Vulnerability Report: GO-2025-4003
- CVE-2025-54286, GHSA-p8hw-rfjg-689h
- Affects: github.com/canonical/lxd
- Published: Nov 05, 2025
CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI in github.com/canonical/lxd
For detailed information about this vulnerability, visit https://github.com/canonical/lxd/security/advisories/GHSA-p8hw-rfjg-689h.
Affected Modules
-
PathGo VersionsCustom Versions*
-
all versions, no known fixedfrom 0.0.0-20220401034332-1e1349e3cbf3 before 0.0.0-20250827065555-0494f5d47e41, from 6.0.0 before 6.5.0, from 5.0.0 before 5.0.5, from 5.1.0 before 5.21.4
*Custom versions, which can't be mapped automatically to standard Go module versions, are ignored by govulncheck. (See this note on versions for more details.)
Aliases
References
- https://github.com/canonical/lxd/security/advisories/GHSA-p8hw-rfjg-689h
- https://vuln.go.dev/ID/GO-2025-4003.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.