Nixpkgs security tracker

Login with GitHub

Published issues

All published security issues are tracked and resolved on GitHub.

NIXPKGS-2026-1384
published 4 months, 1 week ago
Permalink CVE-2026-42146
5.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 4 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored reference https://g…
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

CImg Library: Uncontrolled memory allocation via nb_colors field in _load_bmp


CImg
  • ==< c3aacf5b96ac1e54b7af1957c6737dbf3949f6d3
NIXPKGS-2026-1383
published 4 months, 1 week ago
updated 4 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    9 packages
    • python312Packages.beets-audible
    • python312Packages.beets-minimal
    • python313Packages.beets-audible
    • python313Packages.beets-minimal
    • python314Packages.beets-audible
    • python312Packages.beets-alternatives
    • python314Packages.beets-alternatives
    • python313Packages.beets-alternatives
    • pkgsRocm.python3Packages.beets-audible
  • @LeSuisse restored
    2 packages
    • python312Packages.beets-minimal
    • python313Packages.beets-minimal
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

beets is Vulnerable to XSS


beets
  • ==< 2.10.0
NIXPKGS-2026-1382
published 4 months, 1 week ago
Permalink CVE-2026-43863
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 4 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    12 packages
    • mutter
    • neomutt
    • mutt-ics
    • mutter46
    • mutter48
    • mutt-wizard
    • fontmuttmisc
    • notmuch-mutt
    • font-mutt-misc
    • pantheon.mutter
    • xorg.fontmuttmisc
    • vimPlugins.nvim-treesitter-parsers.muttrc
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

mutt before 2.3.2 has an infinite loop in data_object_to_stream in …


mutt
  • <2.3.2
NIXPKGS-2026-1381
published 4 months, 1 week ago
Permalink CVE-2026-43864
2.5 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 4 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    12 packages
    • mutter
    • neomutt
    • mutt-ics
    • mutter46
    • mutter48
    • mutt-wizard
    • fontmuttmisc
    • notmuch-mutt
    • font-mutt-misc
    • pantheon.mutter
    • xorg.fontmuttmisc
    • vimPlugins.nvim-treesitter-parsers.muttrc
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.


mutt
  • <2.3.2
NIXPKGS-2026-1380
published 4 months, 1 week ago
Permalink CVE-2026-43861
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 4 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    12 packages
    • mutter
    • neomutt
    • mutt-ics
    • mutter46
    • mutter48
    • mutt-wizard
    • fontmuttmisc
    • notmuch-mutt
    • font-mutt-misc
    • pantheon.mutter
    • xorg.fontmuttmisc
    • vimPlugins.nvim-treesitter-parsers.muttrc
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

mutt before 2.3.2 does not check for '\0' in url_pct_decode.


mutt
  • <2.3.2
NIXPKGS-2026-1379
published 4 months, 1 week ago
Permalink CVE-2026-43859
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 4 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    12 packages
    • mutter
    • neomutt
    • mutt-ics
    • mutter46
    • mutter48
    • mutt-wizard
    • fontmuttmisc
    • notmuch-mutt
    • font-mutt-misc
    • pantheon.mutter
    • xorg.fontmuttmisc
    • vimPlugins.nvim-treesitter-parsers.muttrc
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for …


mutt
  • <2.3.2
NIXPKGS-2026-1378
published 4 months, 1 week ago
Permalink CVE-2026-33846
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 4 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    4 packages
    • guile-gnutls
    • python312Packages.python3-gnutls
    • python313Packages.python3-gnutls
    • python314Packages.python3-gnutls
  • @LeSuisse ignored maintainer @vcunat maintainer.ignore
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Gnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly


rhcos
gnutls
gnutls-main
  • *
NIXPKGS-2026-1377
published 4 months, 1 week ago
Permalink CVE-2026-43862
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 4 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    12 packages
    • mutter
    • neomutt
    • mutt-ics
    • mutter46
    • mutter48
    • mutt-wizard
    • fontmuttmisc
    • notmuch-mutt
    • font-mutt-misc
    • pantheon.mutter
    • xorg.fontmuttmisc
    • vimPlugins.nvim-treesitter-parsers.muttrc
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

In mutt before 2.3.2, the imap_auth_gss security level is mishandled.


mutt
  • <2.3.2
https://www.openwall.com/lists/oss-security/2026/05/04/3
NIXPKGS-2026-1376
published 4 months, 1 week ago
Permalink CVE-2026-43860
3.7 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 4 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    12 packages
    • mutter
    • neomutt
    • mutt-ics
    • mutter46
    • mutter48
    • mutt-wizard
    • fontmuttmisc
    • notmuch-mutt
    • font-mutt-misc
    • pantheon.mutter
    • xorg.fontmuttmisc
    • vimPlugins.nvim-treesitter-parsers.muttrc
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

mutt before 2.3.2 sometimes truncates the hash_passwd by one byte …


mutt
  • <2.3.2
https://www.openwall.com/lists/oss-security/2026/05/04/3
NIXPKGS-2026-1375
published 4 months, 1 week ago
updated 4 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    6 packages
    • claude-code-acp
    • claude-code-router
    • gnomeExtensions.claude-code-usage
    • gnomeExtensions.claude-code-switcher
    • vscode-extensions.anthropic.claude-code
    • gnomeExtensions.claude-code-usage-indicator
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Claude Code arbitrary code execution via git worktree commondir trust dialog bypass


claude-code
  • ==>= 2.1.63, < 2.1.84