7ASecurity is proud to publish the results of our independent security audit of Incus, a next-generation system container, application container, and virtual-machine manager. The project was solicited by the Incus maintainers, funded by the Sovereign Tech Agency, and executed by 7ASecurity against the Incus v6.22.0 baseline.
This was the first penetration test for Incus. The engagement combined deep whitebox testing with runtime validation, parser fuzzing, a SLSA-based supply-chain review, and a lightweight threat model. The Incus team was exceptionally responsive throughout the work, provided a realistic test environment, and moved quickly on fixes, advisories, and release coordination.

Audit Process
In March 2026, a team of 8 senior auditors from 7ASecurity dedicated 46 working days to the review. The whitebox methodology included access to a staging environment, documentation, test users, and source code. The scope was organized across six work packages:
- WP1: API Surface & Pre-Auth Exposure Audit
- WP2: Authorization & Restricted Access Audit
- WP3: Guest Isolation, Images, Storage & Networking Audit
- WP4: Parser Fuzzing & Test Case Creation
- WP5: Supply Chain & Release Process Review
- WP6: Lightweight Threat Model
Audit Results
- 14 identified vulnerabilities across WP1-WP4
- 17 hardening recommendations
- 31 documented entries in the revised public report
- All 14 vulnerabilities resolved by Incus and confirmed by 7ASecurity
- 14 of 17 hardening recommendations resolved and confirmed
- Three remaining hardening entries record maintainer decisions or non-issue context rather than open vulnerabilities
- SLSA v1.2 supply-chain and release-process assessment, plus a lightweight threat model
The revised report also addresses the classification points raised during maintainer review. INC-01-016 is recorded as a resolved hardening improvement; INC-01-017 and INC-01-018 are explicitly identified as duplicates of earlier findings and are not counted as separate vulnerabilities; and the report records the maintainer rationale for INC-01-010, INC-01-025, and INC-01-029. Public CVE and GitHub advisory references are included where applicable.
Positive Security Observations
The audit left 7ASecurity with a number of strong positive impressions. Large parts of the codebase appeared mature, professionally developed, and well maintained. The platform showed significant engineering depth, good secure-coding patterns in multiple areas, clear authentication and project-restriction concepts, and strong privilege boundaries around instance filesystems. Malformed and unexpected API requests were generally rejected cleanly without destabilizing the daemon, and the documentation was clear and well organized.
The Incus maintainers deserve particular recognition for their response. Fixes were developed quickly, all vulnerability entries were resolved and verified, public advisories and CVEs were coordinated where appropriate, and the team worked closely with 7ASecurity throughout verification and report review.
Acknowledgements
Thank you to the individuals and organizations that made this engagement possible:
- Stéphane Graber and the rest of the Incus maintainers
- Sovereign Tech Agency for funding the engagement
- 7ASecurity: Abraham Aranguren, Daniel Ortiz, Dariusz Jastrzębski, Dheeraj Joshi, Miroslav Štampar, Nabih Benazzouz, Patrick Ventuzelo, and Szymon Grzybowski
Read the report
You can read the public Incus audit report HERE
You can read Incus's announcement HERE
You can explore the Incus source repository or talk to 7ASecurity about independent security testing for open-source infrastructure.