Nixpkgs security tracker

Login with GitHub

Published issues

All published security issues are tracked and resolved on GitHub.

NIXPKGS-2026-2532
published 9 hours ago
SiYuan before v3.8.2 Private Attribute View Key Enumeration
Permalink CVE-2026-86191
5.3 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 9 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse ignored
    3 maintainers
    • @TomaSajt
    • @mtul0729
    • @L-Trump
    maintainer.ignore
  • @LeSuisse published on GitHub

SiYuan before v3.8.2 Private Attribute View Key Enumeration


siyuan
  • <3.8.2
  • ==3.8.2
NIXPKGS-2026-2531
published 9 hours ago
Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox
Permalink CVE-2026-86197
5.1 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Passive (P)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): Low (L)
  • Subsequent System Impact Integrity (SI): Low (L)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Passive (P)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Low (L)
  • Modified Subsequent System Impact Integrity (MSI): Low (L)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 9 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    19 packages
    • haskellPackages.gravatar
    • gravit
    • antigravity
    • antigravity-cli
    • antigravity-fhs
    • antigravity-ide
    • antigravity-ide-fhs
    • stardust-xr-gravity
    • kdePackages.libgravatar
    • bulwark-plugins.gravatar
    • gnomeExtensions.gravatar
    • python313Packages.libgravatar
    • python314Packages.libgravatar
    • python314Packages.flask-gravatar
    • python313Packages.django-gravatar2
    • python313Packages.flask-gravatar
    • python314Packages.django-gravatar2
    • perlPackages.MojoliciousPluginGravatar
    • perl5Packages.MojoliciousPluginGravatar
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Grav before 2.0.20 Cross-Site Scripting via Assets Sandbox


grav
  • <2.0.20
  • ==2.0.20
NIXPKGS-2026-2530
published 9 hours ago
NetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIs
Permalink CVE-2026-86175
7.1 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 9 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    63 packages
    • netbox2netshot
    • pkgsRocm.netbox
    • pkgsRocm.netbox_4_4
    • netboxPlugins.netbox-bgp
    • netboxPlugins.netbox-dns
    • netboxPlugins.netbox-lists
    • python313Packages.pynetbox
    • python314Packages.pynetbox
    • netboxPlugins.netbox-qrcode
    • netboxPlugins.netbox-routing
    • netboxPlugins.netbox-secrets
    • python313Packages.netbox-bgp
    • python314Packages.netbox-bgp
    • python314Packages.netbox-dns
    • netboxPlugins.netbox-contract
    • netboxPlugins.netbox-security
    • netboxPlugins.netbox-documents
    • netboxPlugins.netbox-inventory
    • netboxPlugins.netbox-lifecycle
    • netboxPlugins.netbox-data-flows
    • python314Packages.netbox-qrcode
    • netboxPlugins.netbox-attachments
    • python313Packages.netbox-routing
    • python314Packages.netbox-routing
    • netboxPlugins.netbox-contextmenus
    • terraform-providers.e-breuninger_netbox
    • python313Packages.netbox-dns
    • python313Packages.netbox-qrcode
    • netboxPlugins.netbox-reorder-rack
    • python313Packages.netbox-contract
    • netboxPlugins.netbox-config-backup
    • netboxPlugins.netbox-napalm-plugin
    • python313Packages.netbox-documents
    • python314Packages.netbox-documents
    • netboxPlugins.netbox-custom-objects
    • netboxPlugins.netbox-topology-views
    • pkgsRocm.python3Packages.netbox-bgp
    • python313Packages.netbox-attachments
    • netboxPlugins.netbox-floorplan-plugin
    • python313Packages.netbox-contextmenus
    • python313Packages.netbox-reorder-rack
    • python314Packages.netbox-contextmenus
    • python314Packages.netbox-reorder-rack
    • pkgsRocm.python3Packages.netbox-qrcode
    • python313Packages.netbox-napalm-plugin
    • pkgsRocm.python3Packages.netbox-routing
    • python313Packages.netbox-topology-views
    • pkgsRocm.python3Packages.netbox-contract
    • netboxPlugins.netbox-plugin-prometheus-sd
    • pkgsRocm.python3Packages.netbox-documents
    • python313Packages.netbox-floorplan-plugin
    • pkgsRocm.python3Packages.netbox-attachments
    • pkgsRocm.python3Packages.netbox-reorder-rack
    • pkgsRocm.python3Packages.netbox-napalm-plugin
    • python313Packages.netbox-plugin-prometheus-sd
    • python314Packages.netbox-plugin-prometheus-sd
    • netboxPlugins.netbox-interface-synchronization
    • pkgsRocm.python3Packages.netbox-topology-views
    • pkgsRocm.python3Packages.netbox-floorplan-plugin
    • python313Packages.netbox-interface-synchronization
    • python314Packages.netbox-interface-synchronization
    • pkgsRocm.python3Packages.netbox-plugin-prometheus-sd
    • pkgsRocm.python3Packages.netbox-interface-synchronization
  • @LeSuisse restored package pkgsRocm.netbox_4_4
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

NetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIs


netbox
  • =<4.7.0
NIXPKGS-2026-2529
published 9 hours ago
Pixelfed through 0.12.9 Unauthorized Story Access via API
Permalink CVE-2026-86178
5.3 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): Low (L)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 9 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Pixelfed through 0.12.9 Unauthorized Story Access via API


pixelfed
  • =<0.12.9
NIXPKGS-2026-2528
published 9 hours ago
gonic before 0.22.0 Missing Administrator Check on the Subsonic startScan Endpoint
Permalink CVE-2026-86118
5.3 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): Low (L)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): Low (L)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 9 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

gonic before 0.22.0 Missing Administrator Check on the Subsonic startScan Endpoint


gonic
  • <0.22.0
Needs a backport.
NIXPKGS-2026-2527
published 9 hours ago
Metabase before 0.63.1 Missing Function-Level Authorization on the Glossary Management API
Permalink CVE-2026-86116
7.1 HIGH
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): High (H)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): High (H)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
updated 9 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Metabase before 0.63.1 Missing Function-Level Authorization on the Glossary Management API


metabase
  • <0.63.1
Needs a backport
NIXPKGS-2026-2526
published 10 hours ago
PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse …
Permalink CVE-2026-86145
8.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
updated 10 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    12 packages
    • jpcre2
    • ocamlPackages.pcre2
    • haskellPackages.pcre2
    • luaPackages.lrexlib-pcre2
    • ocamlPackages_latest.pcre2
    • haskellPackages.regex-pcre2
    • lua51Packages.lrexlib-pcre2
    • lua52Packages.lrexlib-pcre2
    • lua53Packages.lrexlib-pcre2
    • lua54Packages.lrexlib-pcre2
    • lua55Packages.lrexlib-pcre2
    • luajitPackages.lrexlib-pcre2
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse …


PCRE2
  • <10.48
NIXPKGS-2026-2525
published 20 hours ago
libpcap: security issues < 1.10.7
Permalink CVE-2026-31911
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 20 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • darwin.libpcap
    • python313Packages.libpcap
    • python314Packages.libpcap
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

abort() in libpcap before 1.10.7 on an invalid BPF opcode


libpcap
  • <1.10.7
Permalink CVE-2026-0799
8.7 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 20 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • darwin.libpcap
    • python313Packages.libpcap
    • python314Packages.libpcap
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

OOBR and OOBW in libpcap before 1.10.7


libpcap
  • <1.10.7
Permalink CVE-2026-18238
5.0 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 20 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • darwin.libpcap
    • python314Packages.libpcap
    • python313Packages.libpcap
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

OOBR in rpcap client in libpcap before 1.10.7


libpcap
  • <1.10.7
  • ==1.9.x
  • ==1.8.x
Permalink CVE-2026-6554
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 20 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • darwin.libpcap
    • python313Packages.libpcap
    • python314Packages.libpcap
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

infinte loop in libpcap before 1.10.7


libpcap
  • <1.10.7
Permalink CVE-2026-31912
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 20 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • darwin.libpcap
    • python313Packages.libpcap
    • python314Packages.libpcap
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

OOBR in libpcap before 1.10.7


libpcap
  • <1.10.7
Permalink CVE-2026-6244
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 20 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • python314Packages.libpcap
    • python313Packages.libpcap
    • darwin.libpcap
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

division by zero in libpcap before 1.10.7


libpcap
  • <1.10.7
Permalink CVE-2026-18313
4.3 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 20 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • darwin.libpcap
    • python313Packages.libpcap
    • python314Packages.libpcap
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

rpcapd memory leak in libpcap before 1.10.7


libpcap
  • <1.10.7
  • ==1.9.x
NIXPKGS-2026-2524
published 20 hours ago
libxml2: security issues < 2.15.4
Permalink CVE-2026-86143
6.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
updated 20 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • libxml2_13
    • libxml2Python
    • sbclPackages.cl-libxml2
    • perlPackages.AlienLibxml2
    • python313Packages.libxml2
    • python314Packages.libxml2
    • perl5Packages.AlienLibxml2
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback …


libxml2
  • <2.15.4
Permalink CVE-2026-86142
6.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
updated 20 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • libxml2_13
    • libxml2Python
    • sbclPackages.cl-libxml2
    • perlPackages.AlienLibxml2
    • python313Packages.libxml2
    • python314Packages.libxml2
    • perl5Packages.AlienLibxml2
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

In libxml2 before 2.15.4, there is a heap-based buffer overflow …


libxml2
  • <2.15.4
Permalink CVE-2026-86138
6.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
updated 20 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • libxml2_13
    • libxml2Python
    • sbclPackages.cl-libxml2
    • perlPackages.AlienLibxml2
    • python313Packages.libxml2
    • python314Packages.libxml2
    • perl5Packages.AlienLibxml2
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer …


libxml2
  • <2.15.4
Permalink CVE-2026-86144
5.6 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 20 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • libxml2Python
    • sbclPackages.cl-libxml2
    • perlPackages.AlienLibxml2
    • python313Packages.libxml2
    • python314Packages.libxml2
    • perl5Packages.AlienLibxml2
    • libxml2_13
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do …


libxml2
  • <2.15.4
Permalink CVE-2026-86139
6.9 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
updated 20 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • libxml2_13
    • libxml2Python
    • sbclPackages.cl-libxml2
    • perlPackages.AlienLibxml2
    • python313Packages.libxml2
    • python314Packages.libxml2
    • perl5Packages.AlienLibxml2
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer …


libxml2
  • <2.15.4
Permalink CVE-2026-86141
2.9 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 20 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • libxml2_13
    • libxml2Python
    • sbclPackages.cl-libxml2
    • perlPackages.AlienLibxml2
    • python313Packages.libxml2
    • python314Packages.libxml2
    • perl5Packages.AlienLibxml2
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference …


libxml2
  • <2.15.4
Permalink CVE-2026-86137
2.9 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 20 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • libxml2_13
    • libxml2Python
    • sbclPackages.cl-libxml2
    • perlPackages.AlienLibxml2
    • python313Packages.libxml2
    • python314Packages.libxml2
    • perl5Packages.AlienLibxml2
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka …


libxml2
  • <2.15.4
Permalink CVE-2026-86140
8.0 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
updated 20 hours ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    7 packages
    • libxml2_13
    • libxml2Python
    • sbclPackages.cl-libxml2
    • perlPackages.AlienLibxml2
    • python313Packages.libxml2
    • python314Packages.libxml2
    • perl5Packages.AlienLibxml2
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat …


libxml2
  • <2.15.4
NIXPKGS-2026-2523
published 1 day, 16 hours ago
Multiple issues in Ceph<20.2.4
Permalink CVE-2026-50152
9.1 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 1 day, 16 hours ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    8 packages
    • calceph
    • libceph
    • ceph-csi
    • ceph-dev
    • ceph-client
    • kubectl-rook-ceph
    • sbclPackages.cephes
    • haskellPackages.heterocephalus
  • @mweinelt accepted
  • @mweinelt published on GitHub

Ceph Monitor subscription handler improperly authorizes config-key store reads, exposing cluster secrets to read-only users


ceph
  • ==>= 20.0.0, < 20.2.4
  • ==>= 19.0.0, < 19.2.6
Permalink CVE-2025-30156
8.9 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Adjacent (A)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Adjacent (A)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
updated 1 day, 16 hours ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    8 packages
    • calceph
    • libceph
    • ceph-csi
    • ceph-dev
    • ceph-client
    • kubectl-rook-ceph
    • sbclPackages.cephes
    • haskellPackages.heterocephalus
  • @mweinelt accepted
  • @mweinelt published on GitHub

Ceph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and credential forgery


ceph
  • ==< 19.2.6
  • ==>= 20.0.0, < 20.2.4
Permalink CVE-2026-39944
8.8 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 1 day, 16 hours ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    8 packages
    • calceph
    • libceph
    • ceph-csi
    • ceph-dev
    • ceph-client
    • kubectl-rook-ceph
    • sbclPackages.cephes
    • haskellPackages.heterocephalus
  • @mweinelt accepted
  • @mweinelt published on GitHub

Ceph: CephX AES Authentication error


ceph
  • ==>= 20.0.0, < 20.2.4
  • ==>= 19.0.0, < 19.2.6
Permalink CVE-2026-54330
8.1 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 1 day, 16 hours ago by @mweinelt Activity log
  • Created suggestion
  • @mweinelt ignored
    8 packages
    • calceph
    • libceph
    • ceph-csi
    • ceph-dev
    • ceph-client
    • kubectl-rook-ceph
    • sbclPackages.cephes
    • haskellPackages.heterocephalus
  • @mweinelt accepted
  • @mweinelt published on GitHub

Ceph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing privilege escalation


ceph
  • ==>= 20.0.0, < 20.2.4
  • ==>= 19.0.0, < 19.2.6