Published issues
updated 9 hours ago
by @LeSuisse
Activity log
-
Created automatic suggestion
21 hours ago
-
@LeSuisse
accepted
10 hours ago
-
@LeSuisse
published on GitHub
9 hours ago
Apache Airflow: Users with asset materialization permisssions could trigger Dags they had no access to
UI / API User with asset materialize permission could trigger dags they had no access to.
Users are advised to migrate to Airflow version 3.2.0 that fixes the issue.
Matching in nixpkgs
Platform to programmatically author, schedule and monitor workflows
-
-
-
nixos-25.11-small
2.7.3
-
nixpkgs-25.11-darwin
2.7.3
updated 9 hours ago
by @LeSuisse
Activity log
-
Created automatic suggestion
21 hours ago
-
@LeSuisse
accepted
10 hours ago
-
@LeSuisse
published on GitHub
9 hours ago
Apache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1
Secrets in Variables saved as JSON dictionaries were not properly redacted - in case thee variables were retrieved by the user the secrets stored as nested fields were not masked.
If you do not store variables with sensitive values in JSON form, you are not affected. Otherwise please upgrade to Apache Airflow 3.2.0 that has the fix implemented
Matching in nixpkgs
Platform to programmatically author, schedule and monitor workflows
-
-
-
nixos-25.11-small
2.7.3
-
nixpkgs-25.11-darwin
2.7.3
updated 9 hours ago
by @LeSuisse
Activity log
-
Created automatic suggestion
21 hours ago
-
@LeSuisse
accepted
10 hours ago
-
@LeSuisse
published on GitHub
9 hours ago
Apache Airflow: API extra-links triggers XCom deserialization/class instantiation (Airflow 3.1.5)
Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low.
Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.
Matching in nixpkgs
Platform to programmatically author, schedule and monitor workflows
-
-
-
nixos-25.11-small
2.7.3
-
nixpkgs-25.11-darwin
2.7.3
updated 9 hours ago
by @LeSuisse
Activity log
-
Created automatic suggestion
21 hours ago
-
@LeSuisse
accepted
9 hours ago
-
@LeSuisse
published on GitHub
9 hours ago
Apache Airflow: Bad example of BashOperator shell injection via dag_run.conf
An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be used to escalate privileges of UI user to allow execute code on worker. Users should review if any of their own DAGs have adopted this incorrect advice.
Matching in nixpkgs
Platform to programmatically author, schedule and monitor workflows
-
-
-
nixos-25.11-small
2.7.3
-
nixpkgs-25.11-darwin
2.7.3
Permalink
CVE-2026-40491
6.5 MEDIUM
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): LOW
-
Privileges required (PR): NONE
-
User interaction (UI): REQUIRED
-
Scope (S): UNCHANGED
-
Confidentiality impact (C): NONE
-
Integrity impact (I): HIGH
-
Availability impact (A): NONE
updated 9 hours ago
by @LeSuisse
Activity log
-
Created automatic suggestion
21 hours ago
-
@LeSuisse
ignored
6 packages
- hongdown
- lgogdownloader
- lgogdownloader-gui
- python312Packages.gdown
- python313Packages.gdown
- python314Packages.gdown
9 hours ago
-
@LeSuisse
ignored
reference https://g…
9 hours ago
-
@LeSuisse
accepted
9 hours ago
-
@LeSuisse
published on GitHub
9 hours ago
gdown Affected by Arbitrary File Write via Path Traversal in gdown.extractall
gdown is a Google Drive public file/folder downloader. Versions prior to 5.2.2 are vulnerable to a Path Traversal attack within the extractall functionality. When extracting a maliciously crafted ZIP or TAR archive, the library fails to sanitize or validate the filenames of the archive members. This allow files to be written outside the intended destination directory, potentially leading to arbitrary file overwrite and Remote Code Execution (RCE). Version 5.2.2 contains a fix.
Matching in nixpkgs
CLI tool for downloading large files from Google Drive
-
-
-
nixos-25.11-small
5.2.0
-
nixpkgs-25.11-darwin
5.2.0
Ignored packages (6)
Markdown formatter that enforces Hong Minhee's Markdown style conventions
Unofficial downloader to GOG.com for Linux users. It uses the same API as the official GOGDownloader
-
-
nixpkgs-unstable
3.18
-
nixos-unstable-small
3.18
-
-
nixos-25.11-small
3.18
-
nixpkgs-25.11-darwin
3.18
Unofficial downloader to GOG.com for Linux users. It uses the same API as the official GOGDownloader
-
-
nixpkgs-unstable
3.18
-
nixos-unstable-small
3.18
-
-
nixos-25.11-small
3.18
-
nixpkgs-25.11-darwin
3.18
CLI tool for downloading large files from Google Drive
-
-
nixos-25.11-small
5.2.0
-
nixpkgs-25.11-darwin
5.2.0
CLI tool for downloading large files from Google Drive
-
-
-
nixos-25.11-small
5.2.0
-
nixpkgs-25.11-darwin
5.2.0
CLI tool for downloading large files from Google Drive
updated 9 hours ago
by @LeSuisse
Activity log
-
Created automatic suggestion
21 hours ago
-
@LeSuisse
accepted
9 hours ago
-
@LeSuisse
published on GitHub
9 hours ago
Apache Airflow: Exposing stack trace in case of constraint error
In case of SQL errors, exception/stack trace of errors was exposed in API even if "api/expose_stack_traces" was set to false. That could lead to exposing additional information to potential attacker. Users are recommended to upgrade to Apache Airflow 3.2.0, which fixes the issue.
Matching in nixpkgs
Platform to programmatically author, schedule and monitor workflows
-
-
-
nixos-25.11-small
2.7.3
-
nixpkgs-25.11-darwin
2.7.3
Permalink
CVE-2026-33337
7.5 HIGH
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): LOW
-
Privileges required (PR): NONE
-
User interaction (UI): NONE
-
Scope (S): UNCHANGED
-
Confidentiality impact (C): NONE
-
Integrity impact (I): NONE
-
Availability impact (A): HIGH
updated 9 hours ago
by @LeSuisse
Activity log
-
Created automatic suggestion
1 day, 21 hours ago
-
@LeSuisse
ignored
package firebird-emu
9 hours ago
-
@LeSuisse
accepted
9 hours ago
-
@LeSuisse
published on GitHub
9 hours ago
Firebird has a buffer overflow when parsing corrupted slice packets
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when deserializing a slice packet, the xdr_datum() function does not validate that a cstring length conforms to the slice descriptor bounds, allowing a cstring longer than the allocated buffer to overflow it. An unauthenticated attacker can exploit this by sending a crafted packet to the server, potentially causing a crash or other security impact. This issue has been fixed in versions 5.0.4, 4.0.7 and 3.0.14.
Affected products
firebird
-
==>= 5.0.0, < 5.0.4
-
==>= 3.0.0, < 3.0.14
-
==>= 4.0.0, < 4.0.7
Matching in nixpkgs
SQL relational database management system
-
-
-
nixos-25.11-small
4.0.6
-
nixpkgs-25.11-darwin
4.0.6
SQL relational database management system
SQL relational database management system
-
-
-
nixos-25.11-small
4.0.6
-
nixpkgs-25.11-darwin
4.0.6
Ignored packages (1)
Third-party multi-platform emulator of the ARM-based TI-Nspire™ calculators
-
-
nixpkgs-unstable
1.6
-
nixos-unstable-small
1.6
-
-
nixos-25.11-small
1.6
-
nixpkgs-25.11-darwin
1.6
Permalink
CVE-2025-65104
7.9 HIGH
-
CVSS version: 3.1
-
Attack vector (AV): LOCAL
-
Attack complexity (AC): LOW
-
Privileges required (PR): LOW
-
User interaction (UI): NONE
-
Scope (S): CHANGED
-
Confidentiality impact (C): LOW
-
Integrity impact (I): HIGH
-
Availability impact (A): LOW
updated 9 hours ago
by @LeSuisse
Activity log
-
Created automatic suggestion
1 day, 21 hours ago
-
@LeSuisse
ignored
3 packages
- firebird-emu
- firebird
- firebird_4
9 hours ago
-
@LeSuisse
ignored
reference https://g…
9 hours ago
-
@LeSuisse
accepted
9 hours ago
-
@LeSuisse
published on GitHub
9 hours ago
Firebird: Information leak vulnerability in firebird3 client when used with newer server
Firebird is an open-source relational database management system. In versions FB3 of the client library placed incorrect data length values into XSQLDA fields when communicating with FB4 or higher servers, resulting in an information leak. This issue is fixed by upgrading to the FB4 client or higher.
Matching in nixpkgs
SQL relational database management system
Ignored packages (3)
SQL relational database management system
-
-
-
nixos-25.11-small
4.0.6
-
nixpkgs-25.11-darwin
4.0.6
SQL relational database management system
-
-
-
nixos-25.11-small
4.0.6
-
nixpkgs-25.11-darwin
4.0.6
Third-party multi-platform emulator of the ARM-based TI-Nspire™ calculators
-
-
nixpkgs-unstable
1.6
-
nixos-unstable-small
1.6
-
-
nixos-25.11-small
1.6
-
nixpkgs-25.11-darwin
1.6
Permalink
CVE-2026-40338
5.2 MEDIUM
-
CVSS version: 3.1
-
Attack vector (AV): PHYSICAL
-
Attack complexity (AC): LOW
-
Privileges required (PR): NONE
-
User interaction (UI): NONE
-
Scope (S): UNCHANGED
-
Confidentiality impact (C): HIGH
-
Integrity impact (I): NONE
-
Availability impact (A): LOW
updated 9 hours ago
by @LeSuisse
Activity log
-
Created automatic suggestion
1 day, 21 hours ago
-
@LeSuisse
accepted
9 hours ago
-
@LeSuisse
published on GitHub
9 hours ago
libgphoto2 has OOB read in ptp_unpack_Sony_DPD() enumeration count parsing in ptp-pack.c
libgphoto2 is a camera access and control library. Versions up to and including 2.5.33 have an out-of-bounds read in the PTP_DPFF_Enumeration case of `ptp_unpack_Sony_DPD()` in `camlibs/ptp2/ptp-pack.c` (line 856). The function reads a 2-byte enumeration count N via `dtoh16o(data, *poffset)` without verifying that 2 bytes remain in the buffer. The standard `ptp_unpack_DPD()` at line 704 has this exact check, confirming the Sony variant omitted it by oversight. Commit 3b9f9696be76ae51dca983d9dd8ce586a2561845 fixes the issue.
Matching in nixpkgs
Library for accessing digital cameras
Permalink
CVE-2026-33392
7.2 HIGH
-
CVSS version: 3.1
-
Attack vector (AV): NETWORK
-
Attack complexity (AC): LOW
-
Privileges required (PR): HIGH
-
User interaction (UI): NONE
-
Scope (S): UNCHANGED
-
Confidentiality impact (C): HIGH
-
Integrity impact (I): HIGH
-
Availability impact (A): HIGH
updated 9 hours ago
by @LeSuisse
Activity log
-
Created automatic suggestion
1 day, 21 hours ago
-
@LeSuisse
accepted
9 hours ago
-
@LeSuisse
published on GitHub
9 hours ago
In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve …
In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass
Matching in nixpkgs
Issue tracking and project management tool for developers