Database/Control plane, storage & DevOps
Proxmox VE (libpve-storage-perl XXE): XML external entity injection in the Proxmox storage library, reachable
CVE-2026-51080Control plane, storage & DevOpscurated
Impact
XML external entity injection in the Proxmox storage library, reachable unauthenticated, leading to full compromise. Proxmox is increasingly used as the hypervisor for smaller GPU clouds where vSphere licensing does not pencil out.
Who can reach it
Unauthenticated network access to the affected Proxmox service.
What to do
Upgrade libpve-storage-perl past v9.1.1 / v8.3.7 via the Proxmox enterprise or no-subscription repo. Package update plus service restart; no VM downtime required.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.