
CVE-2026-41648 Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs would be unpacked and YAML files parsed witho… https://www.cve.org/CVERecord?id=CVE-2026-41648
Post summary
The CVE-2026-41648 entry describes a flaw in Incus where untrusted tarball files lead to YAML parsing before version 7.0.0. No PoC, patch, or evidence of exploitation is provided.
