Published issues
Permalink
CVE-2026-42310
5.1 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): Low (L)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): Low (L)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
16 hours ago
-
@LeSuisse
ignored
17 packages
- python312Packages.pillow-heif
- python312Packages.pillow-jpls
- python312Packages.pillowfight
- python313Packages.pillow-heif
- python313Packages.pillow-jpls
- python313Packages.pillowfight
- python314Packages.pillow-heif
- python314Packages.pillow-jpls
- python314Packages.pillowfight
- python312Packages.types-pillow
- python313Packages.types-pillow
- python314Packages.types-pillow
- python312Packages.pypillowfight
- python313Packages.pypillowfight
- python314Packages.pypillowfight
- python312Packages.pillow-avif-plugin
- python313Packages.pillow-avif-plugin
3 hours ago
-
@LeSuisse
ignored
maintainer @mweinelt
3 hours ago
maintainer.ignore
-
@LeSuisse
accepted
3 hours ago
-
@LeSuisse
published on GitHub
3 hours ago
Pillow: PDF Parsing Trailer Infinite Loop (DoS)
Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.
Matching in nixpkgs
Friendly PIL fork (Python Imaging Library)
Friendly PIL fork (Python Imaging Library)
Friendly PIL fork (Python Imaging Library)
Ignored packages (17)
Python library for working with HEIF images and plugin for Pillow
-
-
nixos-25.11-small
1.1.0
-
nixpkgs-25.11-darwin
1.1.0
JPEG-LS plugin for the Python Pillow library
-
-
nixos-25.11-small
1.3.2
-
nixpkgs-25.11-darwin
1.3.2
Eases the transition from PIL to Pillow for Python packages
-
-
nixos-25.11-small
0.4
-
nixpkgs-25.11-darwin
0.4
Python library for working with HEIF images and plugin for Pillow
-
-
-
nixos-25.11-small
1.1.0
-
nixpkgs-25.11-darwin
1.1.0
JPEG-LS plugin for the Python Pillow library
-
-
-
nixos-25.11-small
1.3.2
-
nixpkgs-25.11-darwin
1.3.2
Eases the transition from PIL to Pillow for Python packages
-
-
nixpkgs-unstable
0.4
-
nixos-unstable-small
0.4
-
-
nixos-25.11-small
0.4
-
nixpkgs-25.11-darwin
0.4
Python library for working with HEIF images and plugin for Pillow
JPEG-LS plugin for the Python Pillow library
Eases the transition from PIL to Pillow for Python packages
-
-
nixpkgs-unstable
0.4
-
nixos-unstable-small
0.4
Library containing various image processing algorithms
-
-
nixos-25.11-small
0.3.1
-
nixpkgs-25.11-darwin
0.3.1
Library containing various image processing algorithms
-
-
-
nixos-25.11-small
0.3.1
-
nixpkgs-25.11-darwin
0.3.1
Library containing various image processing algorithms
Pillow plugin that adds support for AVIF files
-
-
nixos-25.11-small
1.5.2
-
nixpkgs-25.11-darwin
1.5.2
Pillow plugin that adds support for AVIF files
-
-
nixos-25.11-small
1.5.2
-
nixpkgs-25.11-darwin
1.5.2
Package maintainers
Ignored maintainers (1)
Permalink
CVE-2026-42308
5.1 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): Low (L)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): Low (L)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
16 hours ago
-
@LeSuisse
ignored
17 packages
- python313Packages.pillow-avif-plugin
- python312Packages.pillow-avif-plugin
- python314Packages.pypillowfight
- python313Packages.pypillowfight
- python312Packages.pypillowfight
- python314Packages.types-pillow
- python314Packages.pillowfight
- python314Packages.pillow-jpls
- python314Packages.pillow-heif
- python313Packages.pillowfight
- python313Packages.pillow-jpls
- python313Packages.types-pillow
- python312Packages.types-pillow
- python313Packages.pillow-heif
- python312Packages.pillowfight
- python312Packages.pillow-jpls
- python312Packages.pillow-heif
3 hours ago
-
@LeSuisse
ignored
maintainer @mweinelt
3 hours ago
maintainer.ignore
-
@LeSuisse
accepted
3 hours ago
-
@LeSuisse
published on GitHub
3 hours ago
Pillow: Integer overflow when processing fonts
Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.
Matching in nixpkgs
Friendly PIL fork (Python Imaging Library)
Friendly PIL fork (Python Imaging Library)
Friendly PIL fork (Python Imaging Library)
Ignored packages (17)
Python library for working with HEIF images and plugin for Pillow
-
-
nixos-25.11-small
1.1.0
-
nixpkgs-25.11-darwin
1.1.0
JPEG-LS plugin for the Python Pillow library
-
-
nixos-25.11-small
1.3.2
-
nixpkgs-25.11-darwin
1.3.2
Eases the transition from PIL to Pillow for Python packages
-
-
nixos-25.11-small
0.4
-
nixpkgs-25.11-darwin
0.4
Python library for working with HEIF images and plugin for Pillow
-
-
-
nixos-25.11-small
1.1.0
-
nixpkgs-25.11-darwin
1.1.0
JPEG-LS plugin for the Python Pillow library
-
-
-
nixos-25.11-small
1.3.2
-
nixpkgs-25.11-darwin
1.3.2
Eases the transition from PIL to Pillow for Python packages
-
-
nixpkgs-unstable
0.4
-
nixos-unstable-small
0.4
-
-
nixos-25.11-small
0.4
-
nixpkgs-25.11-darwin
0.4
Python library for working with HEIF images and plugin for Pillow
JPEG-LS plugin for the Python Pillow library
Eases the transition from PIL to Pillow for Python packages
-
-
nixpkgs-unstable
0.4
-
nixos-unstable-small
0.4
Library containing various image processing algorithms
-
-
nixos-25.11-small
0.3.1
-
nixpkgs-25.11-darwin
0.3.1
Library containing various image processing algorithms
-
-
-
nixos-25.11-small
0.3.1
-
nixpkgs-25.11-darwin
0.3.1
Library containing various image processing algorithms
Pillow plugin that adds support for AVIF files
-
-
nixos-25.11-small
1.5.2
-
nixpkgs-25.11-darwin
1.5.2
Pillow plugin that adds support for AVIF files
-
-
nixos-25.11-small
1.5.2
-
nixpkgs-25.11-darwin
1.5.2
Package maintainers
Ignored maintainers (1)
Permalink
CVE-2026-42309
5.1 MEDIUM
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): None (N)
-
Vulnerable System Impact Integrity (VI): None (N)
-
Vulnerable System Impact Availability (VA): Low (L)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): None (N)
-
Modified Vulnerable System Impact Integrity (MVI): None (N)
-
Modified Vulnerable System Impact Availability (MVA): Low (L)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
16 hours ago
-
@LeSuisse
ignored
17 packages
- python312Packages.pillow-heif
- python312Packages.pillow-jpls
- python312Packages.pillowfight
- python313Packages.pillow-heif
- python313Packages.pillow-jpls
- python313Packages.pillowfight
- python314Packages.pillow-heif
- python314Packages.pillow-jpls
- python314Packages.pillowfight
- python312Packages.types-pillow
- python313Packages.types-pillow
- python314Packages.types-pillow
- python312Packages.pypillowfight
- python313Packages.pypillowfight
- python314Packages.pypillowfight
- python312Packages.pillow-avif-plugin
- python313Packages.pillow-avif-plugin
3 hours ago
-
@LeSuisse
ignored
reference https://g…
3 hours ago
-
@LeSuisse
accepted
3 hours ago
-
@LeSuisse
ignored
maintainer @mweinelt
3 hours ago
maintainer.ignore
-
@LeSuisse
published on GitHub
3 hours ago
Pillow: Heap buffer overflow with nested list coordinates
Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates such as ImagePath.Path, ImageDraw.ImageDraw.polygon and ImageDraw.ImageDraw.line could cause a heap buffer overflow, as nested lists were recursively unpacked beyond the allocated buffer. Coordinate lists are now validated to contain exactly two numeric coordinates. This issue has been patched in version 12.2.0.
Matching in nixpkgs
Friendly PIL fork (Python Imaging Library)
Friendly PIL fork (Python Imaging Library)
Friendly PIL fork (Python Imaging Library)
Ignored packages (17)
Python library for working with HEIF images and plugin for Pillow
-
-
nixos-25.11-small
1.1.0
-
nixpkgs-25.11-darwin
1.1.0
JPEG-LS plugin for the Python Pillow library
-
-
nixos-25.11-small
1.3.2
-
nixpkgs-25.11-darwin
1.3.2
Eases the transition from PIL to Pillow for Python packages
-
-
nixos-25.11-small
0.4
-
nixpkgs-25.11-darwin
0.4
Python library for working with HEIF images and plugin for Pillow
-
-
-
nixos-25.11-small
1.1.0
-
nixpkgs-25.11-darwin
1.1.0
JPEG-LS plugin for the Python Pillow library
-
-
-
nixos-25.11-small
1.3.2
-
nixpkgs-25.11-darwin
1.3.2
Eases the transition from PIL to Pillow for Python packages
-
-
nixpkgs-unstable
0.4
-
nixos-unstable-small
0.4
-
-
nixos-25.11-small
0.4
-
nixpkgs-25.11-darwin
0.4
Python library for working with HEIF images and plugin for Pillow
JPEG-LS plugin for the Python Pillow library
Eases the transition from PIL to Pillow for Python packages
-
-
nixpkgs-unstable
0.4
-
nixos-unstable-small
0.4
Library containing various image processing algorithms
-
-
nixos-25.11-small
0.3.1
-
nixpkgs-25.11-darwin
0.3.1
Library containing various image processing algorithms
-
-
-
nixos-25.11-small
0.3.1
-
nixpkgs-25.11-darwin
0.3.1
Library containing various image processing algorithms
Pillow plugin that adds support for AVIF files
-
-
nixos-25.11-small
1.5.2
-
nixpkgs-25.11-darwin
1.5.2
Pillow plugin that adds support for AVIF files
-
-
nixos-25.11-small
1.5.2
-
nixpkgs-25.11-darwin
1.5.2
Package maintainers
Ignored maintainers (1)
Permalink
CVE-2026-42311
8.6 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): None (N)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Vulnerable System Impact Confidentiality (VC): High (H)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): High (H)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): None (N)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Vulnerable System Impact Confidentiality (MVC): High (H)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): High (H)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
16 hours ago
-
@LeSuisse
ignored
17 packages
- python312Packages.pillow-heif
- python312Packages.pillow-jpls
- python312Packages.pillowfight
- python313Packages.pillow-heif
- python313Packages.pillow-jpls
- python313Packages.pillowfight
- python314Packages.pillow-heif
- python314Packages.pillow-jpls
- python314Packages.pillowfight
- python312Packages.types-pillow
- python313Packages.types-pillow
- python314Packages.types-pillow
- python312Packages.pypillowfight
- python313Packages.pypillowfight
- python314Packages.pypillowfight
- python312Packages.pillow-avif-plugin
- python313Packages.pillow-avif-plugin
3 hours ago
-
@LeSuisse
ignored
reference https://g…
3 hours ago
-
@LeSuisse
accepted
3 hours ago
-
@LeSuisse
ignored
maintainer @mweinelt
3 hours ago
maintainer.ignore
-
@LeSuisse
published on GitHub
3 hours ago
Pillow: OOB Write with Invalid PSD Tile Extents (Integer Overflow)
Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.
Matching in nixpkgs
Friendly PIL fork (Python Imaging Library)
Friendly PIL fork (Python Imaging Library)
Friendly PIL fork (Python Imaging Library)
Ignored packages (17)
Python library for working with HEIF images and plugin for Pillow
-
-
nixos-25.11-small
1.1.0
-
nixpkgs-25.11-darwin
1.1.0
JPEG-LS plugin for the Python Pillow library
-
-
nixos-25.11-small
1.3.2
-
nixpkgs-25.11-darwin
1.3.2
Eases the transition from PIL to Pillow for Python packages
-
-
nixos-25.11-small
0.4
-
nixpkgs-25.11-darwin
0.4
Python library for working with HEIF images and plugin for Pillow
-
-
-
nixos-25.11-small
1.1.0
-
nixpkgs-25.11-darwin
1.1.0
JPEG-LS plugin for the Python Pillow library
-
-
-
nixos-25.11-small
1.3.2
-
nixpkgs-25.11-darwin
1.3.2
Eases the transition from PIL to Pillow for Python packages
-
-
nixpkgs-unstable
0.4
-
nixos-unstable-small
0.4
-
-
nixos-25.11-small
0.4
-
nixpkgs-25.11-darwin
0.4
Python library for working with HEIF images and plugin for Pillow
JPEG-LS plugin for the Python Pillow library
Eases the transition from PIL to Pillow for Python packages
-
-
nixpkgs-unstable
0.4
-
nixos-unstable-small
0.4
Library containing various image processing algorithms
-
-
nixos-25.11-small
0.3.1
-
nixpkgs-25.11-darwin
0.3.1
Library containing various image processing algorithms
-
-
-
nixos-25.11-small
0.3.1
-
nixpkgs-25.11-darwin
0.3.1
Library containing various image processing algorithms
Pillow plugin that adds support for AVIF files
-
-
nixos-25.11-small
1.5.2
-
nixpkgs-25.11-darwin
1.5.2
Pillow plugin that adds support for AVIF files
-
-
nixos-25.11-small
1.5.2
-
nixpkgs-25.11-darwin
1.5.2
Package maintainers
Ignored maintainers (1)
Permalink
CVE-2026-45184
6.5 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): Low (L)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): Low (L)
updated
3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
16 hours ago
-
@LeSuisse
accepted
3 hours ago
-
@LeSuisse
published on GitHub
3 hours ago
Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled …
Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used.
Matching in nixpkgs
Free and open source video editor, based on MLT Framework and KDE Frameworks
Free and open source video editor, based on MLT Framework and KDE Frameworks
Permalink
CVE-2026-42296
8.1 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): None (N)
updated
3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
16 hours ago
-
@LeSuisse
ignored
2 references
3 hours ago
-
@LeSuisse
accepted
3 hours ago
-
@LeSuisse
published on GitHub
3 hours ago
Argo Workflows has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, serviceAccountName bypass templateReferencing Strict/Secure
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, a user with create Workflow permission can bypass templateReferencing: Strict to get host network access, switch service accounts, override pod security context, add tolerations to schedule on control-plane nodes, or enable SA token mounting. This defeats the stated purpose of the feature. The practical impact depends on what Kubernetes-level controls are in place. Clusters with PodSecurity admission or OPA/Gatekeeper would independently block some of these (like hostNetwork). Clusters that rely on Argo's Strict mode as the primary enforcement layer are fully exposed. This issue has been patched in versions 3.7.14 and 4.0.5.
Affected products
argo-workflows
-
==< 3.7.14
-
==>= 4.0.0, < 4.0.5
Matching in nixpkgs
Container native workflow engine for Kubernetes
Permalink
CVE-2026-42575
7.5 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): High (H)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): None (N)
updated
3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
16 hours ago
-
@LeSuisse
accepted
3 hours ago
-
@LeSuisse
published on GitHub
3 hours ago
apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible)
apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, apko verifies the signature on APKINDEX.tar.gz but never compares individually downloaded .apk packages against the checksum recorded in the signed index. The checksum is parsed and available via ChecksumString(), and the downloaded package control hash is computed, but the two values are never compared in getPackageImpl(). Mismatched packages are silently accepted. An attacker who can substitute download responses (compromised mirror, HTTP repository, poisoned CDN cache) can install arbitrary packages into built images. This issue has been patched in version 1.2.7.
Matching in nixpkgs
Build OCI images using APK directly without Dockerfile
-
-
-
nixos-25.11-small
1.1.9
-
nixpkgs-25.11-darwin
1.1.9
Permalink
CVE-2026-42246
7.6 HIGH
-
CVSS version (CVSS): 4.0
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Attack Requirement (AT): Present (P)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Passive (P)
-
Vulnerable System Impact Confidentiality (VC): High (H)
-
Vulnerable System Impact Integrity (VI): High (H)
-
Vulnerable System Impact Availability (VA): None (N)
-
Subsequent System Impact Confidentiality (SC): None (N)
-
Subsequent System Impact Integrity (SI): None (N)
-
Subsequent System Impact Availability (SA): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Attack Requirement (MAT): Present (P)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Passive (P)
-
Modified Vulnerable System Impact Confidentiality (MVC): High (H)
-
Modified Vulnerable System Impact Integrity (MVI): High (H)
-
Modified Vulnerable System Impact Availability (MVA): None (N)
-
Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
-
Modified Subsequent System Impact Integrity (MSI): Negligible (N)
-
Modified Subsequent System Impact Availability (MSA): Negligible (N)
-
Safety (S): Not Defined (X)
-
Automatable (AU): Not Defined (X)
-
Recovery (R): Not Defined (X)
-
Value Density (V): Not Defined (X)
-
Vulnerability Response Effort (RE): Not Defined (X)
-
Provider Urgency (U): Not Defined (X)
-
Confidentiality Req. (CR): Not Defined (X)
-
Integrity Req. (IR): Not Defined (X)
-
Availability Req. (AR): Not Defined (X)
-
Exploit Maturity (E): Not Defined (X)
updated
3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
16 hours ago
-
@LeSuisse
ignored
4 packages
- perlPackages.NetIMAPClient
- perl5Packages.NetIMAPClient
- perl538Packages.NetIMAPClient
- perl540Packages.NetIMAPClient
3 hours ago
-
@LeSuisse
ignored
6 references
3 hours ago
-
@LeSuisse
accepted
3 hours ago
-
@LeSuisse
published on GitHub
3 hours ago
net-imap vulnerable to STARTTLS stripping via invalid response timing
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#starttls to return "successfully", without starting TLS. This issue has been patched in versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4.
Affected products
net-imap
-
==>= 0.4.0, < 0.4.24
-
==>= 0.6.0, < 0.6.4
-
==< 0.3.10
-
==>= 0.5.0, < 0.5.14
Ignored packages (4)
Not so simple IMAP client library
Not so simple IMAP client library
Not so simple IMAP client library
Not so simple IMAP client library
Permalink
CVE-2026-6665
8.1 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
16 hours ago
-
@LeSuisse
ignored
package prometheus-pgbouncer-exporter
3 hours ago
-
@LeSuisse
accepted
3 hours ago
-
@LeSuisse
published on GitHub
3 hours ago
PgBouncer buffer overflow in SCRAM
The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend that sends a SCRAM server-final-message with a long nonce can trigger a stack overflow.
Matching in nixpkgs
Lightweight connection pooler for PostgreSQL
Ignored packages (1)
Prometheus exporter for PgBouncer
Permalink
CVE-2026-6666
5.9 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): None (N)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): High (H)
updated
3 hours ago
by @LeSuisse
Activity log
-
Created suggestion
16 hours ago
-
@LeSuisse
ignored
package prometheus-pgbouncer-exporter
3 hours ago
-
@LeSuisse
accepted
3 hours ago
-
@LeSuisse
published on GitHub
3 hours ago
PgBouncer crash in kill_pool_logins_server_error
A possible null pointer reference in PgBouncer before 1.25.2 could lead to a crash, if a server sends an error response without SQLSTATE field.
Matching in nixpkgs
Lightweight connection pooler for PostgreSQL
Ignored packages (1)
Prometheus exporter for PgBouncer