GPU VulnDB

Database/Control plane, storage & DevOps

Proxmox VE (libpve-storage-perl XXE): XML external entity injection in the Proxmox storage library, reachable

CVE-2026-51080Control plane, storage & DevOpscurated

Impact

XML external entity injection in the Proxmox storage library, reachable unauthenticated, leading to full compromise. Proxmox is increasingly used as the hypervisor for smaller GPU clouds where vSphere licensing does not pencil out.

Who can reach it

Unauthenticated network access to the affected Proxmox service.

What to do

Upgrade libpve-storage-perl past v9.1.1 / v8.3.7 via the Proxmox enterprise or no-subscription repo. Package update plus service restart; no VM downtime required.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.