Nixpkgs security tracker

Login with GitHub

Published issues

All published security issues are tracked and resolved on GitHub.

NIXPKGS-2026-0645
published 3 months, 1 week ago
Permalink CVE-2026-30943
4.1 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Changed (C)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 3 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

Gokapi has Privilege Escalation in File Replace


Gokapi
  • ==< 2.2.4
Upstream advisory: https://github.com/Forceu/Gokapi/security/advisories/GHSA-j6jp-78w8-34x6
NIXPKGS-2026-0636
published 3 months, 1 week ago
Permalink CVE-2026-31883
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
updated 3 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

FreeRDP has a `size_t` underflow in ADPCM decoder leads to heap-buffer-overflow write


FreeRDP
  • ==< 3.24.0
Upstream advisory: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-85x9-4xxp-xhm5
Upstream patch: https://github.com/FreeRDP/FreeRDP/commit/16df2300e1e3f5a51f68fb1626429e58b531b7c8
NIXPKGS-2026-0641
published 3 months, 1 week ago
Permalink CVE-2026-29776
3.1 LOW
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): Low (L)
updated 3 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

FreeRDP has an Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core Library


FreeRDP
  • ==< 3.24.0
Upstream advisory: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-c747-x4wf-cqrr
Upstream patch: https://github.com/FreeRDP/FreeRDP/commit/a9e0abf2eac8c2e370fa155bf1abb9d044c0ca8a
NIXPKGS-2026-0638
published 3 months, 1 week ago
updated 3 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

FreeRDP has a Heap Buffer Overflow in nsc_process_message() via Unchecked SURFACE_BITS_COMMAND Bitmap Dimensions


FreeRDP
  • ==< 3.24.0
Upstream advisory: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rrqm-46rj-cmx2
Upstream patch: https://github.com/FreeRDP/FreeRDP/commit/83d9aedea278a74af3e490ff5eeb889c016dbb2b
NIXPKGS-2026-0646
published 3 months, 1 week ago
Permalink CVE-2026-31899
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 3 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

CairoSVG vulnerable to Exponential DoS via recursive <use> element amplification


CairoSVG
  • ==< 2.9.0
Upstream advisory: https://github.com/Kozea/CairoSVG/security/advisories/GHSA-f38f-5xpm-9r7c
Upstream patch: https://github.com/Kozea/CairoSVG/commit/6dde8685ed3f19837767bce7a13a5491e3d0e0bf
NIXPKGS-2026-0650
published 3 months, 1 week ago
Permalink CVE-2026-32597
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
updated 3 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)


pyjwt
  • ==< 2.12.0
Upstream advisory: https://github.com/jpadilla/pyjwt/security/advisories/GHSA-752w-5fwx-jx9f
NIXPKGS-2026-0654
published 3 months, 1 week ago
updated 3 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

SFTPGo improperly sanitizes placeholders in group home directories/key prefixes


sftpgo
  • ==>= 2.3.0, < 2.7.1
Upstream advisory: https://github.com/drakkan/sftpgo/security/advisories/GHSA-m83q-5wr4-4gfp
NIXPKGS-2026-0658
published 3 months, 1 week ago
Permalink CVE-2026-32136
9.8 CRITICAL
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
updated 3 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    3 packages
    • python312Packages.adguardhome
    • python313Packages.adguardhome
    • python314Packages.adguardhome
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

AdGuard Home: HTTP/2 Cleartext (h2c) Upgrade Authentication Bypass


AdGuardHome
  • ==< 0.107.73
Upstream advisory: https://github.com/AdguardTeam/AdGuardHome/security/advisories/GHSA-5fg6-wrq4-w5gh
NIXPKGS-2026-0656
published 3 months, 1 week ago
Permalink CVE-2026-30853
5.0 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Local (L)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): None (N)
  • Integrity (I): Low (L)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Local (L)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): Low (L)
updated 3 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored package calibre-web
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

calibre has a Path Traversal Leading to Arbitrary File Write


calibre
  • ==< 9.5.0
Upstream advisory: https://github.com/kovidgoyal/calibre/security/advisories/GHSA-7mp7-rfrg-542x
NIXPKGS-2026-0652
published 3 months, 1 week ago
Permalink CVE-2026-28356
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): None (N)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): High (H)
updated 3 months, 1 week ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse ignored
    35 packages
    • multipart-parser-c
    • haskellPackages.multipart
    • ocamlPackages.multipart_form
    • haskellPackages.multipart-names
    • ocamlPackages.multipart_form-eio
    • ocamlPackages.multipart_form-lwt
    • perlPackages.HTTPMultiPartParser
    • haskellPackages.servant-multipart
    • ocamlPackages.multipart-form-data
    • ocamlPackages.multipart_form-miou
    • perl5Packages.HTTPMultiPartParser
    • python312Packages.python-multipart
    • python312Packages.sansio-multipart
    • python313Packages.python-multipart
    • python313Packages.sansio-multipart
    • python314Packages.python-multipart
    • python314Packages.sansio-multipart
    • ocamlPackages_latest.multipart_form
    • perl538Packages.HTTPMultiPartParser
    • perl540Packages.HTTPMultiPartParser
    • haskellPackages.http-client-multipart
    • haskellPackages.servant-multipart-api
    • ocamlPackages_latest.multipart_form-eio
    • ocamlPackages_latest.multipart_form-lwt
    • haskellPackages.servant-multipart-client
    • ocamlPackages_latest.multipart-form-data
    • ocamlPackages_latest.multipart_form-miou
    • python312Packages.nested-multipart-parser
    • python313Packages.nested-multipart-parser
    • python314Packages.nested-multipart-parser
    • haskellPackages.autodocodec-servant-multipart
    • chickenPackages_5.chickenEggs.multipart-form-data
    • python312Packages.microsoft-kiota-serialization-multipart
    • python313Packages.microsoft-kiota-serialization-multipart
    • python314Packages.microsoft-kiota-serialization-multipart
  • @LeSuisse accepted
  • @LeSuisse published on GitHub

ReDoS in multipart 1.3.0 - `parse_options_header()`


multipart
  • ==>= 1.3.0, < 1.3.1
  • ==< 1.2.2
Upstream advisory: https://github.com/defnull/multipart/security/advisories/GHSA-p2m9-wcp5-6qw3