Incus is publishing the results of an independent security audit performed by 7ASecurity and funded by the Sovereign Tech Agency. The review covered Incus v6.22.0 and combined whitebox testing, runtime validation, parser fuzzing, a supply-chain assessment, and a lightweight threat model.
Publishing the report is part of our commitment to transparent security work. Incus is a broad and powerful platform spanning system containers, application containers, virtual machines, networking, storage, images, backups, authentication, authorization, and multi-tenant controls. Independent review helps us test those boundaries, improve regression coverage, and give users a clearer picture of the work completed.
Audit Process
In March 2026, 8 senior auditors from 7ASecurity dedicated 46 working days to the engagement. The audit used a whitebox methodology with access to a dedicated environment, documentation, test identities, and source code. The review was organized across the following work packages:
- API Surface & Pre-Auth Exposure
- Authorization & Restricted Access
- Guest Isolation, Images, Storage & Networking
- Parser Fuzzing & Test Case Creation
- Supply Chain & Release Process
- Lightweight Threat Model
Audit Results and Remediation
- 14 identified vulnerabilities
- 17 hardening recommendations
- 31 documented entries in the revised report
- All 14 vulnerabilities resolved and confirmed by 7ASecurity
- 14 of 17 hardening recommendations resolved and confirmed
- Supply-chain review and lightweight threat-model deliverables included
The revised report distinguishes between vulnerabilities, hardening improvements, duplicate traceability entries, and maintainer decisions. Two entries are explicitly marked as duplicates of earlier findings, while the three remaining hardening entries document maintainer rationale or non-issue context rather than unaddressed vulnerabilities.
Incus users and operators should update to the latest available release and consult the public report and linked advisories for the detailed technical record. The revised report includes current CVE and GitHub advisory references where applicable.
Positive Security Observations
The review also recognized substantial existing security strengths. The codebase showed mature engineering and operational polish, with no obvious low-hanging issues across large portions of the reviewed surface. Authentication, transport-security intentions, project restrictions, instance-filesystem boundaries, and API request parsing all showed meaningful defensive design. The project documentation and release process also gave the audit team a strong basis for testing and remediation.
We appreciate the thoroughness of the 7ASecurity team and the support of the Sovereign Tech Agency. Independent reviews like this help us strengthen Incus while providing transparent, actionable information to users, operators, distributions, and downstream projects.
Acknowledgements
Thank you to everyone involved in the engagement:
- 7ASecurity: Abraham Aranguren, Daniel Ortiz, Dariusz Jastrzębski, Dheeraj Joshi, Miroslav Štampar, Nabih Benazzouz, Patrick Ventuzelo, and Szymon Grzybowski
- Stéphane Graber and the Incus maintainer team
- Sovereign Tech Agency
- The Incus users, operators, distributions, and open-source community
Read the report and update
You can read the public Incus audit report HERE
You can read 7ASecurity’s announcement HERE
Learn more about Incus on the project website and browse the source repository.
