CVE-2026-28385 | Canonical lxd up to 6.9 HTTP Service server-side request forgery (EUVD-2026-39805)
A vulnerability categorized as critical has been discovered in Canonical lxd up to 6.9. This affects an unknown function of the component HTTP Service. Such manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2026-28385. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.